APT 22, also identified as Suckfly and G0039, is a China-based threat group that commenced its cyber espionage activities as early as April 2014. The group's primary motivation is intelligence gathering, focusing on obtaining sensitive data rather than immediate financial gain. A distinguishing characteristic of APT 22 is its consistent use of stolen, legitimate code-signing certificates, primarily from South Korean companies, to sign its custom malware and hacking tools. This tactic allows their malicious software to appear trusted, facilitating evasion of security detections. The group operates methodically, often carrying out its campaigns during weekdays, and has primarily directed its efforts against government entities and related organizations in India, as well as businesses in Saudi Arabia.