Mandiant Unmasks APT1 as China's PLA Unit 61398 in Landmark Cyber Espionage Exposé

In a watershed moment for threat intelligence, Mandiant has published a groundbreaking report directly attributing a massive, years-long cyber espionage campaign to Unit 61398 of China's People's Liberation Army (PLA) — the group it tracks as APT1, also known as Comment Crew.

Seven Years, 150 Victims

Mandiant's investigation analyzed intrusions against nearly 150 victims over seven years, beginning no later than 2006. APT1 was assessed as one of the most prolific cyber espionage groups in the world in terms of the sheer volume of stolen information. The firm tracked the group's operations back to four large networks in Shanghai, two of which were allocated directly to the Pudong New Area — the same district housing Unit 61398's headquarters.

Mandiant stated: "The details we have analyzed during hundreds of investigations convince us that the groups conducting these activities are based primarily in China and that the Chinese Government is aware of them."

From Suspicion to Attribution

The report marked a dramatic shift in Mandiant's position. In its 2010 M-Trends report, the firm had stated that "the Chinese government may authorize this activity, but there's no way to determine the extent of its involvement." Three years of additional evidence gathering changed that assessment to direct government sponsorship. Mandiant concluded that APT1 was able to sustain its extensive campaign precisely because it received direct government support.

Operators Behind the Keyboard

In an unprecedented move, Mandiant publicly identified three personas attributed to APT1 operators — individuals the firm characterized as soldiers following orders. The report detailed the group's attack infrastructure, command-and-control systems, and modus operandi across tools, tactics, and procedures. The targeted industries spanned a broad range of sectors, with APT1 conducting espionage against organizations critical to China's strategic interests.

The APT1 report fundamentally changed how the cybersecurity industry approaches nation-state attribution, establishing a template for public threat intelligence reporting that persists to this day. It remains one of the most cited and consequential publications in the history of cyber threat analysis.

Read the full analysis on IntelFusions