APT5 — APT Profile
APT5 is a China-based espionage actor that has been active since at least 2007 primarily targeting the telecommunications, aerospace, and defense industries throughout the U.S., Europe, and Asia. APT5 has displayed advanced tradecraft and significant interest in compromising networking devices and their underlying software including through the use of zero-day exploits.Also tracked as
Mulberry Typhoon, MANGANESE, BRONZE FLEETWOOD, Keyhole Panda, UNC2630
Tools & malware
- gh0st RAT Remote Access Trojan
- Mimikatz Credential Harvesting
- Net Network Reconnaissance
- netstat Network Reconnaissance
- PACEMAKER Backdoor
- PcShare Backdoor
- PoisonIvy Remote Access Trojan
- PULSECHECK Web Shell
- RAPIDPULSE Backdoor
- Skeleton Key Credential Harvesting
- SLIGHTPULSE Web Shell
- SLOWPULSE Backdoor
- Tasklist Discovery
Vendor research
- How Microsoft names threat actors Microsoft
- Digital threats from East Asia increase in breadth and effectiveness Microsoft Threat Intelligence
- Digital threats from East Asia increase in breadth and effectiveness Microsoft
- APT5: Citrix ADC Threat Hunting Guidance NSA
- SOUTHEAST ASIA: AN EVOLVING CYBER THREAT LANDSCAPE FireEye
- Re-Checking Your Pulse: Updates on Chinese APT Actors Compromising Pulse Secure VPN Devices Mandiant
- Secureworks CTU. (n.d.). BRONZE FLEETWOOD Secureworks
- Check Your Pulse: Suspected APT Actors Leverage Authentication Bypass Techniques and Pulse Secure Zero-Day Mandiant
- Mandiant. (n.d.). Advanced Persistent Threats (APTs) Mandiant