Knowledge is Power

Sitewide Search

Search Bare Metal Cyber

Search exact control and technique identifiers, Cyber Wiki articles, framework records, playbooks, books, podcasts, Academy courses, and individual lessons.

ATT&CK Campaign AnalysisIntermediate

Operation Wocao (C0014)

A defensive guide to the Enterprise ATT&CK campaign record C0014, including chronology, evidence, behavior mapping, and resilience lessons. The official record summarizes public reporting describing a global cyber-espionage campaign reported against governments, managed-service providers, and many industries.

Framework mapping

MITRE ATT&CK® Enterprise mapping

Catalog v19.2

Canonical ATT&CK entity profile. Identifier, name, associated-name context, and public-reporting scope were reconciled to the official Enterprise ATT&CK directory; the official object page remains controlling for complete and current relationships.

What this ATT&CK campaign record represents

Operation Wocao (C0014) is an Enterprise ATT&CK campaign record. ATT&CK uses Campaign for a grouping of intrusion activity conducted over a specific period with common targets and objectives. A campaign can be attributed, unattributed, or involve more than one participating cluster.

The official directory summarizes public reporting that describes a global cyber-espionage campaign reported against governments, managed-service providers, and many industries. This BMC page focuses on how to analyze that record defensibly rather than reproducing harmful operational detail.

The public campaign name is a reporting label. Other sources may use overlapping names or define the activity window differently.

Separate the campaign from the actor

A campaign is a time-bounded activity set; a group is an analytic cluster that may participate in many campaigns. Treating those objects as interchangeable can erase chronology, hide changes in tooling, and overstate attribution.

For Operation Wocao, record which source makes each actor, software, infrastructure, target, and technique association. Preserve disagreements instead of forcing every report into one narrative.

  • Record the observed start and end dates or the source’s stated uncertainty.
  • Distinguish direct attribution from similarity, overlap, or speculation.
  • Track each organization’s campaign and group definitions separately.
  • Note where multiple actors may have performed different operational roles.

Build a campaign timeline

Chronology is the backbone of campaign analysis. Place public-reporting events and local observations on the same time axis, but label the source and confidence of every event.

Use phases that support defensive decisions: preparation, initial access, foothold, privilege or identity expansion, discovery, lateral movement, collection, impact, response, and post-incident activity. Do not infer a missing phase merely because it appears in another campaign.

  • Use normalized UTC timestamps while retaining original time-zone context.
  • Link each timeline event to a source passage or telemetry record.
  • Mark first seen, last seen, publication date, and discovery date separately.
  • Identify collection gaps that could make activity appear to stop or start artificially.

Map behaviors without turning ATT&CK into a checklist

Campaign-to-technique relationships in ATT&CK reflect publicly reported observations. They represent a subset of known activity and can change as new reporting is added.

For Operation Wocao, map only behaviors supported by evidence. For every mapping, capture the observable action, affected technology, data source, time window, confidence, and alternative interpretation.

A missing technique does not prove the behavior did not occur, and a mapped technique does not prove it occurred in a different victim environment.

Defensive lessons and coverage questions

Campaign analysis should produce decisions: telemetry improvements, exposed-service review, identity hardening, detection tests, segmentation changes, recovery validation, supplier assurance, or intelligence-collection priorities.

  • Which campaign behaviors are relevant to technologies and trust boundaries actually used by the organization?
  • Which behaviors would create high-consequence outcomes even if they are unlikely?
  • Can the organization reconstruct the sequence with current log coverage and retention?
  • Which controls were preventive, detective, investigative, containment, or recovery measures?
  • What evidence would distinguish this campaign from commodity or unrelated activity?

Investigation and threat-hunting workflow

Use Operation Wocao as a structured hypothesis, not as a keyword hunt. Begin with the most reliable observable, define a time and asset scope, test for related behaviors, and document both confirming and disconfirming evidence.

Threat hunting should not introduce unsafe tools or live adversary infrastructure. Use approved indicators, passive historical data, synthetic tests, and isolated lab material.

  • Validate source reliability and indicator freshness.
  • Search for behavior sequences, not only isolated hashes or domains.
  • Compare affected assets with the campaign’s reported target and technology scope.
  • Escalate based on local evidence and consequence, not the fame of the campaign name.
  • Retire or revise the hypothesis when evidence no longer supports it.

Lessons-learned and resilience review

After analysis, convert the campaign into a small set of reusable control and intelligence requirements. Record what the organization could see, what it could not see, which controls were tested, and what recovery dependencies remain.

Revisit the record when ATT&CK, the underlying public reports, or your environment changes. Versioning keeps a historical assessment from silently becoming a current claim.

Safe practitioner exercise

Using the official C0014 page and one underlying public source, create a campaign timeline with five evidence-backed events. Map no more than three techniques and include one alternative explanation for each mapping.

Finish with one telemetry improvement, one detection test, one containment consideration, and one recovery question. Use only public, synthetic, or sanitized information.

Version, attribution, and independence

This page was reviewed against Enterprise ATT&CK v19.2. Verify the official C0014 record for current dates, associated campaigns, groups, software, techniques, and references.

© 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation.

MITRE ATT&CK® and ATT&CK® are registered trademarks of The MITRE Corporation. Bare Metal Cyber is not affiliated with or endorsed by MITRE. The instructional analysis on this page is original Bare Metal Cyber content.

Certification relevance

This subject appears in or supports the following certification bodies of knowledge:

CompTIA Security+CompTIA CySA+GIAC GCTIISC2 CISSP

Authoritative sources

Continue Learning

Continue with a related Bare Metal Cyber course.