Group 72

This is a collection of rules based on the presence of indicators of compromise publicly reported as associated with this malicious actor.

Group 72 is a cyber espionage group suspected to be associated with the Chinese government. This group is responsible for the Operation SMN campaign. While both this group and the Winnti group use the malware Winnti for Windows, the two groups appear to be distinct based on differences in reporting on the groups' TTPs and targeting.