{"actor":{"id":"apt73","name":"APT73","aliases":[],"vendor_names":{"mandiant":"APT73"},"mitre_gid":null,"type":"nation-state","type_verbatim":"State-sponsored APT","secondary_types":[],"origin":null,"origins":["XX"],"targets":[],"target_regions":[],"sectors":[],"threat_types":[],"mitre_techniques":["T1003","T1027","T1041","T1071","T1078","T1082","T1560","T1566","T1573","T1583"],"gir_codes":["5.5.1","5.1.1","5.2.11","5.2.9","4.2.6"],"active_since":null,"brief":"APT73 is a state-sponsored advanced persistent threat actor whose precise national origin remains unattributed or undisclosed, operating under the designation assigned by Mandiant. The group conducts cyber espionage operations consistent with nation-state objectives, focusing on the collection of sensitive information to support government or strategic interests. Their targeting profile and specific victim sectors remain insufficiently documented in open-source reporting, making detailed characterization of their operational scope uncertain at this time.","attribution_sponsor":null,"attribution_confidence":null,"merged_into":null,"split_from":[],"created_at":"2026-05-20T09:50:19.106695+00:00","updated_at":"2026-05-20T15:12:51.008+00:00","url":"https://aptatlas.net/actors/apt73"},"exports":{"stix":"https://aptatlas.net/api/v1/actors/apt73/stix","navigator":"https://aptatlas.net/api/v1/actors/apt73/navigator"}}