Gold Open Source
ExplorePackagesVulnerabilitiesCWEsMCP ServersScan
Login
Gold Open Source

The authoritative source for production-ready open-source components. Every package, container image, AI model, and MCP server undergoes rigorous verification for security, malware, and license compliance.

Explore Gold

  • Explore Everything
  • Packages
  • Gold Certified Packages
  • Container Images
  • AI Models
  • MCP Servers
  • Agent Skills
  • Chip Manufacturers

Security Data & Tools

  • Scan Your Dependencies
  • Trending Threats
  • Threat RSS Feeds
  • CVE Database
  • Actively Exploited (KEV)
  • SGZ Zero-Days
  • CWE Index
  • MITRE ATT&CK
  • Malicious Packages
  • Security Glossary
  • Supply-Chain Report
  • Developers (API & Badge)
  • Chrome Extension
  • Credits & Data Sources

Products

  • The Platform
  • ESSCM
  • Portal
  • TPRM
  • OSM
  • Cowork
  • Code / Runner
  • Guard

Use Cases

  • Know Your Software
  • Auto-Fix Vulnerabilities
  • Asset Discovery
  • AI Governance
  • MCP Server Security
  • Supply Chain Compliance
  • Zero-Day Discovery
  • All Use Cases

Company

  • About
  • Pricing
  • Blog
  • Documentation
  • Safeguard Academy
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 Gold Open Source. All rights reserved.

Built with care bySafeguard
Home/ATT&CK/Campaigns/C0014
MITRE ATT&CK Campaign · 2017–2019

Operation Wocao (C0014)

ShareXLinkedInRedditHN

[Operation Wocao](https://attack.mitre.org/campaigns/C0014) was a cyber espionage campaign that targeted organizations around the world, including in Brazil, China, France, Germany, Italy, Mexico, Portugal, Spain, the United Kingdom, and the United States. The suspected China-based actors compromised government organizations and managed service providers, as well as aviation, construction, energy, finance, health care, insurance, offshore engineering, software development, and transportation companies.(Citation: FoxIT Wocao December 2019) Security researchers assessed the [Operation Wocao](https://attack.mitre.org/campaigns/C0014) actors used similar TTPs and tools as APT20, suggesting a possible overlap. [Operation Wocao](https://attack.mitre.org/campaigns/C0014) was named after an observed command line entry by one of the threat actors, possibly out of frustration from losing webshell access.(Citation: FoxIT Wocao December 2019)

▪Techniques used (70)

T1012Query RegistryT1003.001LSASS MemoryT1056.001KeyloggingT1518.001Security Software DiscoveryT1018Remote System DiscoveryT1573.002Asymmetric CryptographyT1587.001MalwareT1059.003Windows Command ShellT1555.005Password ManagersT1552.004Private KeysT1119Automated CollectionT1049System Network Connections DiscoveryT1585.002Email AccountsT1124System Time DiscoveryT1571Non-Standard PortT1686.003Windows Host FirewallT1111Multi-Factor Authentication InterceptionT1190Exploit Public-Facing ApplicationT1090.003Multi-hop ProxyT1074.001Local Data StagingT1033System Owner/User DiscoveryT1071.001Web ProtocolsT1569.002Service ExecutionT1005Data from Local SystemT1115Clipboard DataT1583.004ServerT1560.001Archive via UtilityT1106Native APIT1069.001Local GroupsT1078Valid AccountsT1135Network Share DiscoveryT1070.004File DeletionT1685.005Clear Windows Event LogsT1001Data ObfuscationT1588.002ToolT1558.003KerberoastingT1021.002SMB/Windows Admin SharesT1570Lateral Tool TransferT1059.005Visual BasicT1016.001Internet Connection DiscoveryT1087.002Domain AccountT1078.002Domain AccountsT1055Process InjectionT1083File and Directory DiscoveryT1589Gather Victim Identity InformationT1059.006PythonT1112Modify RegistryT1090.001Internal ProxyT1090ProxyT1041Exfiltration Over C2 ChannelT1036.005Match Legitimate Resource Name or LocationT1007System Service DiscoveryT1120Peripheral Device DiscoveryT1003.006DCSyncT1027.005Indicator Removal from ToolsT1053.005Scheduled TaskT1082System Information DiscoveryT1027.010Command ObfuscationT1059.001PowerShellT1047Windows Management InstrumentationT1046Network Service DiscoveryT1095Non-Application Layer ProtocolT1016System Network Configuration DiscoveryT1133External Remote ServicesT1505.003Web ShellT1518Software DiscoveryT1680Local Storage DiscoveryT1105Ingress Tool TransferT1078.003Local AccountsT1057Process Discovery

▪Software used (9)

S0104netstattoolS0521BloodHoundtoolS0002MimikatztoolS0183TortoolS0645WevtutiltoolS0194PowerSploittoolS0105dsquerytoolS0029PsExectoolS0357Impackettool
C0014on MITRE ATT&CK →

MITRE ATT&CK® is a registered trademark of The MITRE Corporation. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation.