APT1

πŸ”΄ High
Also known as: APT1, Brown Fox, Byzantine Candor, Comment Crew, Comment Group, Comment Panda, COMMENT PANDA, G0006, GIF89a, Group 3, PLA Unit 61398, ShadyRAT, Shanghai Group, TG-8223

APT1 is a Chinese cyber espionage group that has been conducting cyber espionage against a broad range of victims.

🌍 Country China
πŸ“… Activity 2006 β€” 2023
⚑ Risk Level High
🎯 Incident Type Espionage
🧭 ATT&CK G0006
Government Defense Technology Private sector
2006
2023

Introduction

APT1 is a Chinese cyber espionage group that has been conducting cyber espionage against a broad range of victims.

Activities and Tactics

Targeted Sectors: Government, Defense, Technology, Private sector

Country of Origin: πŸ‡¨πŸ‡³ China

Risk Level: High

First Seen: 2006

Last Activity: 2023

Incident Type: Espionage

Suspected Victims: United States, Taiwan, Israel, Norway, United Arab Emirates, United Kingdom, Singapore, India, Belgium, South Africa…

Notable Campaigns

  • Shady RAT
  • GhostNet

Tactics, Techniques, and Procedures (TTPs)

ATT&CK technique IDs (denormalized)

Notable Indicators of Compromise (IOCs)

No atomic indicators are listed in this profile. The APTnotes snapshot indexes 2 public reports that may contain IOCs; see Source Attribution for dataset links.

Malware and Tools

  • Hacking Team UEFI Rootkit
  • WEBC2:
  • BISCUIT and many others:

MITRE ATT&CK Software

Attribution and Evidence

Country of Origin: China Additional attribution information pending cataloguing.

References

[1] mitre-attack [6] Mandiant APT1 Mandiant. (n.d.). APT1 Exposing One of China’s Cyber Espionage Units. Retrieved July 18, 2016. [7] CrowdStrike Putter Panda Crowdstrike Global Intelligence Team. (2014, June 9). CrowdStrike Intelligence Report: Putter Panda. Retrieved January 22, 2016.