APT40 — APT Profile
Leviathan is an espionage actor targeting organizations and high-value targets in defense and government. Active since at least 2014, this actor has long-standing interest in maritime industries, naval defense contractors, and associated research institutions in the United States and Western Europe.Also tracked as
Leviathan, MUDCARP, Kryptonite Panda, Gadolinium, BRONZE MOHAWK, TEMP.Jumper, TEMP.Periscope, Gingham Typhoon, Hazel Typhoon, GADOLINIUM
Tools & malware
- js.airbreak Backdoor
- js.cactustorch Loader
- js.nanhaishu Backdoor
- js.scanbox Reconnaissance Framework
- win.badflick Backdoor
- win.blackcoffee Backdoor
- win.chinachopper Web Shell
- win.cobalt_strike Adversary Simulation
- win.dadjoke Backdoor
- win.dadstache Backdoor
- win.derusbi Backdoor
- win.ghost_rat Remote Access Trojan
- win.grillmark Backdoor
- win.homefry Backdoor
- win.lazycat Backdoor
- win.lunchmoney Backdoor
- win.murkytop Backdoor
- win.plugx Backdoor
- win.sedll Backdoor
- win.zxshell Remote Access Trojan
Vendor research
- Mudcarp's Focus on Submarine Technologies Accenture iDefense Unit
- Two Birds, One Stone Panda Adam Kozy
- Leviathan: Espionage actor spearphishes maritime and defense targets Axel F, Pierre T
- Microsoft Security - Detecting Empires in the Cloud Ben Koehl, Joe Hannon
- People’s Republic of China (PRC) Ministry of State Security APT40 Tradecraft in Action CISA et al
- (AA21-200A) Joint Cybersecurity Advisory – Tactics, Techniques, and Procedures of Indicted APT40 Actors Associated with China’s MSS Hainan State Security Department CISA
- Suspected Chinese Cyber Espionage Group (TEMP.Periscope) Targeting U.S. Engineering and Maritime Industries FireEye
- How Microsoft names threat actors Microsoft
- APT40: Examining a China-Nexus Espionage Actor Plan, F., et al
- Threat Profile - BRONZE MOHAWK SecureWorks