admin@338 — APT Profile
admin@338 is a China-based cyber threat group. It has previously used newsworthy events as lures to deliver malware and has primarily targeted organizations involved in financial, economic, and trade policy, typically using publicly available RATs such as PoisonIvy, as well as some non-public backdoors.Description reproduced from MITRE ATT&CK. © The MITRE Corporation, reproduced and distributed with permission.
Also tracked as
TEMPER PANDA, MAGNESIUM, G0018
Tools & malware
- BUBBLEWRAP Backdoor
- ipconfig Network Reconnaissance
- LOWBALL Backdoor
- Net Network Reconnaissance
- netstat Network Reconnaissance
- PoisonIvy Remote Access Trojan
- Systeminfo Discovery