logo

APT19 (DEEP PANDA): A Persistent China-Aligned Espionage and Credential Theft Actor

ID: 4b4bbd48-0cdc-58d4-9fae-777370ffcfe3

STIX ID: report--4b4bbd48-0cdc-58d4-9fae-777370ffcfe3

Feed Name: Brandefense Blog

Threat Score
85/100

Date Published: 2026-03-09

Date Updated: 2026-04-27

Author: BRANDEFENSE

...
...

**APT19 (Deep Panda)** is a China-aligned, hybrid espionage and credential-theft actor active since at least 2013 that conducts sustained phishing, web compromise (web shells), and credential harvesting campaigns—often targeting governments, technology and defense firms, and managed service providers across the United States, Europe, and East Asia—to maintain long-term access and facilitate resale or reuse of credentials for intelligence collection.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.