Cyber Resilience

Threat actor · all actors

APT12G0005 state

🇨🇳 CN

aka APT12, IXESHE, DynCalc, Numbered Panda, DNSCALC, TG-2754, BeeBus, Group 22, Calc Team, Crimson Iron, BRONZE GLOBE, Hexagon Typhoon

Last updated: 2026-08-22

1attributed CVEs
9ATT&CK techniques
1.2IDF score (tooling uniqueness)
0exclusive CVEs
2026years active

About this actor

[APT12](https://attack.mitre.org/groups/G0005) is a threat group that has been attributed to China. The group has targeted a variety of victims including but not limited to media outlets, high-tech companies, and multiple governments.(Citation: Meyers Numbered Panda)

Source: MITRE ATT&CK

Names & naming systems

Each vendor coins its own name for the same actor. Where a name follows a known scheme we attribute it; the rest are listed honestly as unclassified.

MITRE ATT&CKG-number catalogue id

G0005

Microsoftweather-system names

Hexagon Typhoon

CrowdStrikenation-animal names

Numbered Panda

Mandiant / genericAPT numbering

APT12

Secureworkscolour-metal names

BRONZE GLOBE

Unclassifiedno scheme matched

IXESHEDynCalcDNSCALCTG-2754BeeBusGroup 22Calc TeamCrimson Iron

How we know this

Data origin
MITRE ATT&CK Imported from the MITRE ATT&CK STIX bundle as an intrusion-set object.
Techniques
MITRE ATT&CK STIX mappings — 9 ATT&CK techniques on file.
Named victims
None on file.

See how actor data is built for the full pipeline.

Activity timeline

Profile

CVERiskCVSSEPSSPublishedProducts
CVE-2026-20929 5.97.50.01162026-01-13see CVE

Mitigating controls (NIST 800-53)

ControlTechniques coveredCoverage
AC-48 / 989%
CA-78 / 989%
SC-78 / 989%
SI-38 / 989%
SI-48 / 989%
CM-26 / 967%
CM-66 / 967%
SC-445 / 956%
CM-74 / 944%
SI-24 / 944%
SI-84 / 944%
SC-203 / 933%
SI-73 / 933%
IA-92 / 922%
SI-102 / 922%

Co-occurring actors

Similar actors

Similar TTPs

Overlapping CVEs

Same nation-state