Threat actor · all actors
NaikonG0019 state
🇨🇳 CN
aka Naikon, PLA Unit 78020, OVERRIDE PANDA, Camerashy, BRONZE GENEVA, G0019, BRONZE STERLING, G0013, NAIKON CASTLE
Last updated: 2026-08-22
About this actor
[Naikon](https://attack.mitre.org/groups/G0019) is assessed to be a state-sponsored cyber espionage group attributed to the Chinese People’s Liberation Army’s (PLA) Chengdu Military Region Second Technical Reconnaissance Bureau (Military Unit Cover Designator 78020).(Citation: CameraShy) Active since at least 2010, [Naikon](https://attack.mitre.org/groups/G0019) has primarily conducted operations against government, military, and civil organizations in Southeast Asia, as well as against international bodies such as the United Nations Development Programme (UNDP) and the Association of Southeast Asian Nations (ASEAN).(Citation: CameraShy)(Citation: Baumgartner Naikon 2015) While [Naikon](https://attack.mitre.org/groups/G0019) shares some characteristics with [APT30](https://attack.mitre.org/groups/G0013), the two groups do not appear to be exact matches.(Citation: Baumgartner Golovkin Naikon 2015)
Source: MITRE ATT&CK
Names & naming systems
Each vendor coins its own name for the same actor. Where a name follows a known scheme we attribute it; the rest are listed honestly as unclassified.
MITRE ATT&CKG-number catalogue id
CrowdStrikenation-animal names
Secureworkscolour-metal names
Unclassifiedno scheme matched
How we know this
- Data origin
- MITRE ATT&CK Imported from the MITRE ATT&CK STIX bundle as an intrusion-set object.
- Techniques
- MITRE ATT&CK STIX mappings — 23 ATT&CK techniques on file.
- Named victims
- 2 extracted from reporting.
See how actor data is built for the full pipeline.
Activity timeline
- 2022 — 1 KEV added
- 2010 — 1 CVE published
Profile
| CVE | Risk | CVSS | EPSS | Published | Products |
|---|---|---|---|---|---|
CVE-2010-3333 KEV | 8.5 | 7.8 | 0.9740 | 2010-11-10 | see CVE |
T1016System Network Configuration Discovery ↗T1018Remote System Discovery ↗T1036Masquerading ↗T1036.004Masquerade Task or Service ↗T1036.005Match Legitimate Resource Name or Location ↗T1046Network Service Discovery ↗T1047Windows Management Instrumentation ↗T1053Scheduled Task/Job ↗T1053.005Scheduled Task ↗T1078Valid Accounts ↗T1078.002Domain Accounts ↗T1137Office Application Startup ↗T1137.006Add-ins ↗T1204User Execution ↗T1204.002Malicious File ↗T1518Software Discovery ↗T1518.001Security Software Discovery ↗T1547Boot or Logon Autostart Execution ↗T1547.001Registry Run Keys / Startup Folder ↗T1566Phishing ↗T1566.001Spearphishing Attachment ↗T1574Hijack Execution Flow ↗T1574.001DLL ↗
Mitigating controls (NIST 800-53)
| Control | Techniques covered | Coverage |
|---|---|---|
CM-6 | 16 / 23 | 70% |
SI-4 | 15 / 23 | 65% |
CM-2 | 14 / 23 | 61% |
CM-7 | 11 / 23 | 48% |
SI-3 | 11 / 23 | 48% |
AC-6 | 10 / 23 | 43% |
CA-7 | 9 / 23 | 39% |
RA-5 | 9 / 23 | 39% |
AC-2 | 8 / 23 | 35% |
AC-3 | 8 / 23 | 35% |
SI-2 | 7 / 23 | 30% |
SI-7 | 7 / 23 | 30% |
AC-4 | 6 / 23 | 26% |
AC-5 | 6 / 23 | 26% |
CM-5 | 6 / 23 | 26% |
Co-occurring actors
- Scarlet Mimic 1 shared CVEs
- Aoqin Dragon 1 shared CVEs
- Transparent Tribe 1 shared CVEs
- Sandworm Team 1 shared CVEs
Similar actors
Overlapping CVEs
- Transparent Tribe 1.00
- Aoqin Dragon 1.00
- Sandworm Team 0.50
- Scarlet Mimic 0.33
Active in same years
- APT29 2.00
- Equation 2.00
- Threat Group-3390 2.00
- Scarlet Mimic 2.00
- Lotus Blossom 2.00
Same nation-state
- Night Dragon 1.00
- FunnyDream 1.00
- Operation Wocao 1.00
- C0017 1.00
- Cutting Edge 1.00
Same category
- Night Dragon 1.00
- FunnyDream 1.00
- C0011 1.00
- Operation Wocao 1.00
- Operation Dream Job 1.00