Home/Threat Actor/APT1
Threat Actor

APT1

apt1_commentcrew · china · active since 2006

APT1 (Comment Crew / Comment Group / Comment Panda / Byzantine Candor / Shanghai Group / TG-8223 / G0006 / PLA Unit 61398) is a Chinese state-sponsored cyber-espionage actor attributed to the People's Liberation Army General Staff Department 3rd Department 2nd Bureau (Unit 61398) in Shanghai, active from at least 2006 through approximately 2015.

the subject of Mandiant's foundational February 2013 'APT1' report, the public-attribution document that established the modern threat-intelligence template, and of the May 2014 US DOJ indictment of five PLA Unit 61398 officers, the first-ever US criminal indictment of uniformed officers of a foreign military for cyber-espionage; documented operations include sustained intellectual-property theft from 141+ organizations across 20+ industries via 937 C2 servers and 2,500+ domains, the signature WEBC2 HTML-comment C2 channel that gave the group its name, the 2012-2013 intrusions of the New York Times, Wall Street Journal, and Washington Post China desks, and a 40+ custom-malware-family toolkit catalogued in Mandiant's Appendix C.

activity dropped substantially after the May 2014 DOJ indictment and Xi Jinping's late-2015 PLA reorganization folded Unit 61398 into the consolidated Strategic Support Force.

china confidence: high 24 aliases MITRE ATT&CK G0006 ↗

Profile

APT1 is a Chinese state-sponsored cyber-espionage actor formally attributed to the People's Liberation Army (PLA) General Staff Department's 3rd Department, 2nd Bureau, Unit 61398, headquartered in a 12-storey building off Datong Road in the Pudong New Area of Shanghai. The group is historically pivotal: Mandiant's February 18, 2013 'APT1: Exposing One of China's Cyber Espionage Units' report was the foundational public attribution of sustained state-directed cyber-espionage to a named foreign military unit, and established the threat-intelligence template every subsequent vendor has followed. The May 2014 US Department of Justice indictment of five PLA Unit 61398 officers (Wang Dong, Sun Kailiang, Wen Xinyu, Huang Zhenyu, Gu Chunhui) was the first-ever US criminal indictment of uniformed officers of a foreign military for cyber-espionage, a precedent later applied to GRU and RGB officers.

Operational scale and tempo: Mandiant documented 141+ victim organizations across 20+ industries (with strong alignment to China's strategic emerging industries per the 12th Five-Year Plan), 937 confirmed C2 servers across 13 countries, 2,500+ domains, hundreds of terabytes of exfiltrated intellectual property over a 7+ year tracking window beginning around 2006, a longest-documented single-victim intrusion of nearly 5 years, and a largest-documented single-victim theft of 6.5 terabytes in 10 months. Targeting heavily emphasized English-speaking countries (the US foremost, then Canada, the UK, and other Western targets). The name 'Comment Crew' / 'Comment Group' derives from the group's signature WEBC2 backdoor family, which retrieved commands hidden inside HTML comment tags on attacker-controlled web pages, a stealthy C2 channel pattern.

The group operated a 40+ malware-family toolkit documented in Mandiant's Appendix C digital appendix, including WEBC2 (Adspace / Ausov / Bolid / CSON / DipSind / GreenCat / Head / KT3 / MVB / QBP / Rave / Table / Tock / TabMSgSQL / Yahoo variants), Biscuit, Bangat, Bouncer, Combos, GdocUpload, GetMail, GoGet, GLASSES, Hauser, LightBolt, ManitSme, MAPIget, Newsreels, RevIRD, SEASALT, StarsyPound, Tarsip-Eclipse, Tarsip-Moon, and many others. Tradecraft was thorough but unsophisticated by current standards: spear-phishing with attachments exploiting MS Office and Adobe vulnerabilities, custom-malware deployment for persistence, credential theft via Mimikatz/gsecdump, lateral movement via pass-the-hash and PsExec, and large-scale RAR-archived exfiltration over FTP and HTTP. Operations followed Beijing business hours (the FireEye 'PLA and the 8:00am-5:00pm Work Day' confirmation), reinforcing the salaried-military attribution.

Following the May 2014 DOJ indictment, APT1-attributed activity dropped substantially. Xi Jinping's late-2015 PLA reorganization creating the Strategic Support Force (SSF) subsumed Unit 61398's operations into the consolidated cyber organization, and successor activity has since been tracked under other Chinese cluster names. APT1 is now generally considered a historical actor, but one whose personnel, tooling lineages, and tradecraft patterns persist in successor PLA cyber units, and whose attribution methodology fundamentally reshaped the threat- intelligence industry.

Aliases

24
apt1comment crewcomment groupcomment pandabyzantine candorbyzantine hadesshanghai grouptg-8223tg 8223group 3gif89abrown foxshady ratpla unit 61398unit 613983plathird department2nd bureausecond bureau61398 unitmucd 61398g0006apt 1apt-1

Notable Campaigns

8
2015-2016PLA Reorganization, Strategic Support Force (Late 2015)
2014-2015Post-Indictment Operational Quiet Period (2014-2015)
2014US DOJ Indictment of Five PLA Unit 61398 Officers (May 2014)
2013-2014Post-Disclosure Tooling Refresh (2013-2014)
2013Mandiant APT1 Report (February 18, 2013), Foundational Public Attribution
2012-2013New York Times / Wall Street Journal / Washington Post Intrusions
2011Operation Shady RAT (Disclosed August 2011)
2011RSA SecurID Breach Overlap (March 2011)

Attribution & Reporting

Attributed by
MandiantFireEyeUS Department of JusticeFBICISANSAUS Cyber CommandUS Department of StateUS Department of TreasuryCrowdStrikeSymantecCisco TalosTrend MicroKasperskyCyber SquaredThreatConnectDell SecureWorksMicrosoftBooz Allen HamiltonCouncil on Foreign RelationsVerizon DBIRPWCThe New York TimesThe Wall Street Journal
Key reporting
reportMandiant: APT1, Exposing One of China's Cyber Espionage Units (February 18, 2013)
reportMandiant: APT1 Appendix C, Digital Appendix and Indicators (February 2013)
reportUS DOJ Indictment 14-118: USA v. Wang Dong et al. (May 19, 2014), Five PLA Unit 61398 Officers
reportFBI Wanted Notice, Five Chinese Military Hackers Charged with Cyber Espionage
reportFireEye: The PLA and the 8:00am-5:00pm Work Day, FireEye Confirms DOJ's Findings on APT1 Intrusion Activity (May 2014)
reportCrowdStrike Global Intelligence Team: Putter Panda Report (June 2014)
reportSymantec: Comment Crew, Indicators of Compromise
reportMcAfee: Operation Shady RAT (August 2011)
reportCyber Squared / ThreatConnect: APT1 Continued Operations Post-Disclosure (Spring 2013)
reportCouncil on Foreign Relations: PLA Unit 61398, Cyber Operations Tracker
reportNew York Times: Chinese Army Unit Is Seen as Tied to Hacking Against U.S. (David Sanger, February 2013)
reportNew York Times: Chinese Hackers Infiltrate New York Times Computers (January 2013)
reportWashington Post: Chinese Army Unit Is Tied to Hacking Against U.S. (February 2013)
reportMalwarebytes: The Advanced Persistent Threat Files, APT1 (February 2019)
reportEuRepoC: APT Profile, APT 1

Operational

State sponsor

People's Liberation Army (PLA) General Staff Department (GSD) 3rd Department, 2nd Bureau, Unit 61398, headquartered in a 12-storey building off Datong Road in the Pudong New Area of Shanghai. Forensically attributed by Mandiant in their landmark February 2013 'APT1' report.

reinforced by the May 2014 US Department of Justice indictment of five PLA Unit 61398 officers.

Motivations
espionage, intelligence_gathering, intellectual_property_theft, industrial_espionage, economic_advantage, five_year_plan_alignment, strategic_industries_targeting
Sectors
Regions

Detection Blind Spots

60 techniques
Across this actor’s 60 mapped techniques, the share covered by each detection layer. Low bars are where you’d be blind if this actor targeted you.
Behavioral / log (Sigma)58/60 · 96%
Analytics (MITRE CAR)34/60 · 56%
Runtime / container (Falco)5/60 · 8%
File / malware (YARA)0/60 · 0%
Network (Suricata/Snort)15/60 · 25%
Vuln scan (Nuclei)0/60 · 0%

Atomic Test Plan

30 techniques
Runnable Atomic Red Team tests covering this actor’s mapped techniques - validate your detections against this specific adversary. Cross-reference the blind spots above. For authorized lab / purple-team use. Open the full builder
Intelligence Graph · click any node to traverse
CVETechnique ActorTool Family
drag to reposition · click any node to traverse · button top-right enlarges
External lookups - second-class, for what we don’t hold ourselves
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh  ·  Open-source threat intelligence platform  ·  100+ authoritative sources  ·  Every fact traces to its origin