Overview
Operation Wocao (MITRE ATT&CK ID C0014) was a cyber espionage campaign that targeted organizations around the world, per MITRE’s campaign profile — including Brazil, China, France, Germany, Italy, Mexico, Portugal, Spain, the United Kingdom, and the United States. MITRE documents the suspected China-based actors as compromising government organizations and managed service providers, as well as aviation, construction, energy, finance, healthcare, insurance, offshore engineering, software development, and transportation companies.
MITRE’s citations note security researchers assessed the Operation Wocao actors used similar TTPs and tools as APT20, suggesting a possible overlap. Per MITRE’s description, the campaign was named after an observed command-line entry by one of the threat actors — possibly out of frustration from losing webshell access (“wocao” being a Mandarin expletive).
Timeline
Per MITRE ATT&CK’s ingested data, this campaign’s documented activity window runs from December 2017 to December 2019.
Tools involved (per MITRE ATT&CK relationship data)
MITRE ATT&CK’s relationship data for this campaign does not link a formally tracked group entity (consistent with the “suspected,” unconfirmed APT20 overlap noted in MITRE’s description), but documents extensive tooling: BloodHound, Mimikatz, Tor, Wevtutil, PowerSploit, dsquery, PsExec, Impacket, and netstat.
What we don’t have
MITRE’s own documentation flags the China-based attribution and APT20 overlap as an assessment rather than a confirmed fact, and our ingested relationship data has no formal group-attribution edge for this campaign. We have no independent telemetry or IOC data beyond MITRE’s STIX bundle.
Frequently Asked Questions
What was Operation Wocao? A cyber espionage campaign by suspected China-based actors, per MITRE ATT&CK, active from December 2017 to December 2019, targeting government, MSP, and multi-industry victims across ten countries.
Where does the name “Wocao” come from? Per MITRE’s description, from an observed command-line entry by one of the threat actors — possibly out of frustration from losing webshell access.
Is Operation Wocao linked to a named threat group? MITRE ATT&CK notes a suspected TTP/tooling overlap with APT20, but this is described as an assessment, not a confirmed formal attribution, and no group-attribution relationship exists in our ingested data.
Data sourced from MITRE ATT&CK® (https://attack.mitre.org), campaign ID C0014, aggregated September 3, 2026. This product uses MITRE ATT&CK data but is not endorsed or certified by MITRE. See more campaign profiles.