APT5 — APT Profile
APT5 is a China-based espionage actor that has been active since at least 2007 primarily targeting the telecommunications, aerospace, and defense industries throughout the U.S., Europe, and Asia. APT5 has displayed advanced tradecraft and significant interest in compromising networking devices and their underlying software including through the use of zero-day exploits.Description reproduced from MITRE ATT&CK. © The MITRE Corporation, reproduced and distributed with permission.
Also tracked as
Mulberry Typhoon, MANGANESE, BRONZE FLEETWOOD, Keyhole Panda, UNC2630, TEMP.Bottle, Poisoned Flight, BASALT CASTLE
Tools & malware
- gh0st RAT Remote Access Trojan
- Mimikatz Credential Harvesting
- Net Network Reconnaissance
- netstat Network Reconnaissance
- PACEMAKER Backdoor
- PcShare Backdoor
- PoisonIvy Remote Access Trojan
- PULSECHECK Web Shell
- RAPIDPULSE Backdoor
- Skeleton Key Credential Harvesting
- SLIGHTPULSE Web Shell
- SLOWPULSE Backdoor
- Tasklist Discovery
Vendor research
- Advanced Persistent Threats (APTs) Mandiant
- Check Your Pulse: Suspected APT Actors Leverage Authentication Bypass Techniques and Pulse Secure Zero-Day Perez, D. et al
- Re-Checking Your Pulse: Updates on Chinese APT Actors Compromising Pulse Secure VPN Devices Perez, D. et al
- BRONZE FLEETWOOD Secureworks CTU
- How Microsoft names threat actors Microsoft
- Digital threats from East Asia increase in breadth and effectiveness Microsoft Threat Intelligence
- SOUTHEAST ASIA: AN EVOLVING CYBER THREAT LANDSCAPE FireEye
- Re-Checking Your Pulse: Updates on Chinese APT Actors Compromising Pulse Secure VPN Devices Mandiant
- Digital threats from East Asia increase in breadth and effectiveness Microsoft
- APT5: Citrix ADC Threat Hunting Guidance NSA
- Secureworks CTU. (n.d.). BRONZE FLEETWOOD Secureworks
- Mandiant. (n.d.). Advanced Persistent Threats (APTs) Mandiant
- Check Your Pulse: Suspected APT Actors Leverage Authentication Bypass Techniques and Pulse Secure Zero-Day Mandiant