Cyber Resilience

Threat actor · all actors

NaikonG0019 state

🇨🇳 CN

aka Naikon, PLA Unit 78020, OVERRIDE PANDA, Camerashy, BRONZE GENEVA, G0019, BRONZE STERLING, G0013, NAIKON CASTLE

Last updated: 2026-08-22

1attributed CVEs
23ATT&CK techniques
2.7IDF score (tooling uniqueness)
0exclusive CVEs
2010–2022years active

About this actor

[Naikon](https://attack.mitre.org/groups/G0019) is assessed to be a state-sponsored cyber espionage group attributed to the Chinese People’s Liberation Army’s (PLA) Chengdu Military Region Second Technical Reconnaissance Bureau (Military Unit Cover Designator 78020).(Citation: CameraShy) Active since at least 2010, [Naikon](https://attack.mitre.org/groups/G0019) has primarily conducted operations against government, military, and civil organizations in Southeast Asia, as well as against international bodies such as the United Nations Development Programme (UNDP) and the Association of Southeast Asian Nations (ASEAN).(Citation: CameraShy)(Citation: Baumgartner Naikon 2015) While [Naikon](https://attack.mitre.org/groups/G0019) shares some characteristics with [APT30](https://attack.mitre.org/groups/G0013), the two groups do not appear to be exact matches.(Citation: Baumgartner Golovkin Naikon 2015)

Source: MITRE ATT&CK

Names & naming systems

Each vendor coins its own name for the same actor. Where a name follows a known scheme we attribute it; the rest are listed honestly as unclassified.

MITRE ATT&CKG-number catalogue id

G0019G0013

CrowdStrikenation-animal names

OVERRIDE PANDA

Secureworkscolour-metal names

BRONZE GENEVABRONZE STERLING

Unclassifiedno scheme matched

NaikonPLA Unit 78020CamerashyNAIKON CASTLE

How we know this

Data origin
MITRE ATT&CK Imported from the MITRE ATT&CK STIX bundle as an intrusion-set object.
Techniques
MITRE ATT&CK STIX mappings — 23 ATT&CK techniques on file.
Named victims
2 extracted from reporting.

See how actor data is built for the full pipeline.

Activity timeline

Profile

CVERiskCVSSEPSSPublishedProducts
CVE-2010-3333 KEV8.57.80.97402010-11-10see CVE

Mitigating controls (NIST 800-53)

ControlTechniques coveredCoverage
CM-616 / 2370%
SI-415 / 2365%
CM-214 / 2361%
CM-711 / 2348%
SI-311 / 2348%
AC-610 / 2343%
CA-79 / 2339%
RA-59 / 2339%
AC-28 / 2335%
AC-38 / 2335%
SI-27 / 2330%
SI-77 / 2330%
AC-46 / 2326%
AC-56 / 2326%
CM-56 / 2326%

Co-occurring actors

Similar actors

Similar TTPs

Active in same years

Same nation-state