AdversaryGraph public intelligence page
This page is part of Threat Matrix, the public browser workspace for the main AdversaryGraph platform. Use it for ATT&CK pivots, actor and technique context, similarity leads, detection coverage review, and analyst-ready investigation paths.
Validation disclaimer: TTP overlap, actor similarity, generated summaries, and coverage findings are investigation leads, not attribution proof or operational validation without analyst review.
Main AdversaryGraph project Documentation Malware Analysis GitHub
APT19
Aliases: Codoso, C0d0so0, Codoso Team, Sunshop Group
APT19 is a Chinese-based threat group that has targeted a variety of industries, including defense, finance, energy, pharmaceutical, telecommunications, high tech, education, manufacturing, and legal services. In 2017, a phishing campaign was used to target seven law and investment firms. Some analysts track APT19 and Deep Panda as the same group, but it is unclear from open source information if the groups are the same.
Open interactive actor investigation
ATT&CK techniques
Registry Run Keys / Startup FolderT1059.001
PowerShellT1564.003
Hidden WindowT1016
System Network Configuration DiscoveryT1033
System Owner/User DiscoveryT1218.011
Rundll32T1112
Modify RegistryT1189
Drive-by CompromiseT1543.003
Windows ServiceT1071.001
Web ProtocolsT1059
Command and Scripting InterpreterT1027.013
Encrypted/Encoded FileT1566.001
Spearphishing AttachmentT1204.002
Malicious FileT1082
System Information DiscoveryT1132.001
Standard EncodingT1588.002
ToolT1574.002
DLL Side-LoadingT1218.010
Regsvr32T1140
Deobfuscate/Decode Files or InformationT1027.010
Command Obfuscation
Correlated CTI and IR reports
Continue the investigation
Cyber Knowledge routes
These contextual routes explain behaviors associated with this ATT&CK group record. They support learning and investigation planning; they do not add attribution evidence.
Blue Team & Defensive Security · explicit-idModule 5 — Threat hunting
Blue Team & Defensive Security · explicit-nameWindows endpoint and identity forensics
Digital Forensics & Incident Response (DFIR) · explicit-nameModule 10 — Cloud, containers, Kubernetes, and SaaS defense
Blue Team & Defensive Security · topic-matchModule 1 — Mission, authorization, and methodology
Red Team & Offensive Security · topic-matchModule 6 — Alert triage, investigation, and escalation
Blue Team & Defensive Security · topic-matchSecure AI development lifecycle and production release gate
AI Security · topic-matchModule 2 — Asset, service, identity, and exposure context
Blue Team & Defensive Security · topic-matchModule 7 — Endpoint defense and EDR
Blue Team & Defensive Security · topic-matchEvidence integrity, order of volatility, and chain of custody
Digital Forensics & Incident Response (DFIR) · topic-matchLinux and macOS endpoint forensics
Digital Forensics & Incident Response (DFIR) · topic-matchContainer image, registry, runtime, and host security
Cloud Security · topic-match