Wekby, also widely known as APT18, is a Chinese nation-state-aligned cyber espionage group active since at least 2009. The group is assessed to be directly supported by and aligned with the Chinese People's Liberation Navy. Wekby's primary motivation is information theft and cyber espionage, with the aim of advancing China's industries by exfiltrating sensitive data and intellectual property from targeted entities. A distinguishing characteristic of Wekby is its rapid exploitation of zero-day vulnerabilities, often shortly after their public disclosure, including developing its own zero-day exploits. The group is known to have leveraged vulnerabilities like CVE-2015-5119 from the Hacking Team leak. Wekby operates under numerous aliases, including APT18, Dynamite Panda, TG-0416, Scandium, Satin Typhoon, Threat Group-0416, and G0026.