Aurora Panda, also identified as APT17, Axiom, Hidden Lynx, and Group 72, is a state-sponsored cyber espionage group with confirmed ties to the Chinese Ministry of State Security. Documented operations began as early as 2008, driven by the objective of gathering intelligence and stealing information to serve Chinese economic and strategic interests. The group is recognized for its consistent utilization of zero-day exploits, leveraging a framework referred to as the "Elderwood platform" for rapid exploit deployment. It employs sophisticated command and control obfuscation, notably embedding encoded data within legitimate web services like Microsoft TechNet. The group's extensive array of aliases often leads to its activities being associated with, and sometimes distinguished from, other Chinese state-sponsored entities; however, its core focus remains on strategic intelligence gathering rather than financially motivated cybercrime.