Elderwood
Chinese cyberespionage intrusion set publicly attributed to a Beijing-based group and best known for Operation Aurora — a mid-2009 to January 2010 campaign against Google, Adobe, Juniper Networks, and approximately 30 other technology, defense, and supply-chain firms. Google's January 12 2010 'A new approach to China' blog post publicly disclosed the intrusion and China's role. The 'Elderwood Project' name was coined by Symantec in 2012 after a shared zero-day-delivery framework — the Elderwood platform — used across multiple simultaneously-run supply-chain and watering-hole campaigns against defense manufacturers and NGOs.
Aliases
Motivations
Target sectors
Target countries
Diamond Model
Caltagirone / Pendergast / Betz 2013 — four-vertex attribution framework.
MITRE ATT&CK techniques
Timeline
0 eventsIndicators of compromise
0 indicatorsRelated actors
shared ATT&CK techniques- KP · DPRKAPT373 shared techniques
- RU · RussiaRomCom2 shared techniques
- IR · IranAPT341 shared technique
- IR · IranAPT391 shared technique
- ?? · UnknownBlackSuit1 shared technique
- RU · RussiaCOLDRIVER1 shared technique
References
cite this page
Threat Intel Tracker. (2026-05-19). Elderwood — actor profile. Retrieved from https://threatintel.local/actors/elderwood