Cyber Resilience

Threat actor · all actors

APT17G0025 state

🇨🇳 CN

aka APT17, Deputy Dog, Group 8, AURORA PANDA, Hidden Lynx, Tailgater Team, Dogfish, BRONZE KEYSTONE, G0025, Group 72, G0001, Axiom, HELIUM, Heart Typhoon

Last updated: 2026-08-20

0attributed CVEs
3ATT&CK techniques
0.0IDF score (tooling uniqueness)
0exclusive CVEs
years active

About this actor

[APT17](https://attack.mitre.org/groups/G0025) is a China-based threat group that has conducted network intrusions against U.S. government entities, the defense industry, law firms, information technology companies, mining companies, and non-government organizations. (Citation: FireEye APT17)

Source: MITRE ATT&CK

Names & naming systems

Each vendor coins its own name for the same actor. Where a name follows a known scheme we attribute it; the rest are listed honestly as unclassified.

MITRE ATT&CKG-number catalogue id

G0025G0001

Microsoftweather-system names

Heart Typhoon

CrowdStrikenation-animal names

AURORA PANDAHidden Lynx

Mandiant / genericAPT numbering

APT17

Secureworkscolour-metal names

BRONZE KEYSTONE

Unclassifiedno scheme matched

Deputy DogGroup 8Tailgater TeamDogfishGroup 72AxiomHELIUM

How we know this

Data origin
MITRE ATT&CK Imported from the MITRE ATT&CK STIX bundle as an intrusion-set object.
Techniques
MITRE ATT&CK STIX mappings — 3 ATT&CK techniques on file.
Named victims
None on file.

Thin data: Only 3 ATT&CK techniques mapped — a thin behavioural profile; absence is not evidence of a narrow toolkit.

See how actor data is built for the full pipeline.

Activity timeline

No activity events recorded.

Profile

CVERiskCVSSEPSSPublishedProducts
No attributed CVEs.

Co-occurring actors

None.

Similar actors

Similar TTPs

Same nation-state