APT30

πŸ”΄ High
Also known as: APT30, G0013, Raspberry Typhoon, RADIUM, LotusBlossom, LOTUS PANDA, Spring Dragon, ST Group, DRAGONFISH, BRONZE ELGIN, ATK1, G0030, Red Salamander, Lotus BLossom, Billbug, Lotus Blossom

APT30 is a threat group suspected to be associated with the Chinese government. While Naikon shares some characteristics with APT30, the two groups do not appear to be exact matches. FireEye APT30 Baumgartner Golovkin Naikon 2015

🌍 Country China
⚑ Risk Level High
🎯 Incident Type Espionage
🧭 ATT&CK G0013
Government Military Government, Administration

Introduction

APT30 is a threat group suspected to be associated with the Chinese government. While Naikon shares some characteristics with APT30, the two groups do not appear to be exact matches. FireEye APT30 Baumgartner Golovkin Naikon 2015

Activities and Tactics

Targeted Sectors: Government, Military, Government, Administration

Country of Origin: πŸ‡¨πŸ‡³ China

Risk Level: High

Incident Type: Espionage

Suspected Victims: United States, South Korea, Saudi Arabia, Thailand, Vietnam, Malaysia, India, Japan, Philippines, Hong Kong…

Notable Campaigns

Information pending cataloguing.

Tactics, Techniques, and Procedures (TTPs)

Notable Indicators of Compromise (IOCs)

No curated IOCs are currently published for this actor. This section will be updated when stable, attributable indicators are available.

Malware and Tools

MITRE ATT&CK Software

Attribution and Evidence

Country of Origin: China Additional attribution information pending cataloguing.

References

[1] MITRE ATT&CK MITRE ATT&CK entry [2] FireEye APT30 [3] Baumgartner Golovkin Naikon 2015