FBI and CISA Expose APT40: China's MSS-Linked Hainan Hackers Indicted for Global Espionage Campaign

A joint cybersecurity advisory released by the FBI and CISA on July 20, 2021 formally exposed the tactics, techniques, and procedures of APT40 — a Chinese state-sponsored intrusion group operating out of Haikou, Hainan Province — alongside a DOJ indictment unsealed the previous day naming four specific actors linked to the PRC's Ministry of State Security (MSS) Hainan State Security Department (HSSD).

From Front Company to Federal Indictment

The DOJ indictment identified MSS intelligence officers Ding Xiaoyang, Zhu Yunmin, and Cheng Qingmin as directing cyber network exploitation (CNE) operations through front company Hainan Xiandun Technology Development Company, with employee Wu Shurong executing the intrusions. Wu's operations resulted in the theft of trade secrets, intellectual property, and high-value information from private companies and foreign governments across multiple countries — a direct window into how Chinese intelligence services use commercial cover entities to conduct offensive cyber operations with a degree of plausible deniability.

Targeting Scope: Strategic Industries and Belt and Road Alignment

Active since at least 2009, APT40 — also tracked as Leviathan, BRONZE MOHAWK, MUDCARP, Gadolinium, Kryptonite Panda, Temp.Periscope, and Temp.Jumper among other aliases — has targeted governmental organizations, companies, and universities across the United States, Canada, Europe, the Middle East, and the South China Sea region. Targeted sectors include academia, aerospace and aviation, biomedical research, the defense industrial base, healthcare, manufacturing, maritime, rail and shipping transportation, and research institutes. Notably, the advisory highlights that APT40 has specifically targeted industries included in China's Belt and Road Initiative, suggesting the group's espionage activity directly serves Beijing's economic and geopolitical expansion strategy.

TTPs: Credential Theft, Lateral Movement, and Custom Malware

APT40 employs a broad library of custom and open-source malware — much of it shared with other suspected Chinese APT groups — across a full-spectrum intrusion methodology. Initial access is achieved primarily through compromised user and administrator credentials. Once inside a network, the group uses lateral movement techniques to navigate toward high-value assets before executing data exfiltration. A documented operational security nuance: APT40 actors placed legitimate administrative tools such as PuTTY, cmd.exe, and svchost.exe in non-standard directories on victim systems, weaponizing trusted binaries in ways designed to blend with normal system activity and complicate IOC-based detection. Incident responders are advised to assess not just the presence of these tools but their location on disk when triaging potential APT40 compromises.

IOC and Detection Guidance

The advisory covers APT40 CNE activity documented between 2009 and 2018, providing MD5 malware hashes, domains, and file names as indicators. CISA and the FBI emphasize a defense-in-depth approach for mitigation, with priority recommendations including: timely patching of internet-facing systems; enforcing multi-factor authentication for webmail, VPN, and privileged accounts; monitoring DNS queries for C2 tunneling; logging administrative commands such as net, ipconfig, and ping; and implementing allowlisting or baseline comparisons against Windows event logs and network traffic to detect anomalous administrative share mapping.

Attribution and Geopolitical Context

The joint advisory positions APT40 within a pattern of Chinese state-sponsored cyber activity that has drawn formal attribution statements from multiple Western governments. The group's sustained focus on biomedical, maritime, and defense research — combined with its structural ties to the MSS through a documented front company and named intelligence officers — makes this one of the most thoroughly attributed Chinese APT operations on record, and a landmark example of the U.S. government's shift toward public indictments as a deterrence instrument against nation-state cyber actors.

Read the full analysis on IntelFusions