Home/Threat Actor/APT40
Threat Actor

APT40

apt40_leviathan · china · active since 2009

APT40 (Leviathan / MUDCARP / Kryptonite Panda / GADOLINIUM / Gingham Typhoon / BRONZE MOHAWK / TEMP.Periscope / TEMP.Jumper / FEVERDREAM / GreenCrash / Hellsing / TA423 / G0065) is a Chinese state-sponsored cyber-espionage actor attributed to the People's Republic of China Ministry of State Security, Hainan State Security Department, operating from Haikou via the front company Hainan Xiandun Technology Development Company, formally established by the July 2021 US DOJ indictment of four MSS officers and a coordinated eight-government / NATO attribution statement.

active since at least 2009, APT40's defining strategic mission is maritime-domain intelligence collection supporting PLA Navy modernization and South China Sea objectives, with sustained targeting of naval defense contractors, submarine technology research, autonomous underwater vehicles, sonar systems, and maritime research universities, alongside broad targeting of Cambodian elections, Belt and Road Initiative partner states, Southeast Asia, Pacific Island nations, and the March 2024 first formal New Zealand attribution of the 2021 NZ parliamentary network breach and the 2024 first-ever Samoan attribution of cyber attacks to Chinese state actors.

tradecraft hallmarks include exceptionally rapid n-day vulnerability exploitation, SOHO router infrastructure compromise for operational staging, the ScanBox web-based reconnaissance framework, DLL side-loading via legitimately- signed binaries, and the China Chopper / Derusbi / PlugX / Cobalt Strike post-exploitation chain.

china confidence: high 33 aliases MITRE ATT&CK G0065 ↗

Profile

APT40 is a Chinese state-sponsored cyber-espionage actor formally attributed to the People's Republic of China Ministry of State Security (MSS), Hainan State Security Department (HSSD), operating from Haikou, Hainan Province via the front company Hainan Xiandun Technology Development Company. The July 19, 2021 US Department of Justice indictment of four MSS officers (Ding Xiaoyang, Cheng Qingmin, Zhu Yunmin) and Hainan Xiandun operator Wu Shurong established this attribution and was accompanied by one of the largest coordinated multi-government attribution statements ever issued, same-day formal attribution from the US, European Union, United Kingdom, Australia, Canada, New Zealand, Japan, and NATO. Active since at least 2009, APT40 is one of the longest-running and most operationally significant of the provincial MSS cyber clusters. APT40's defining strategic role is maritime-domain intelligence collection in support of PLA Navy modernization and Chinese objectives in the South China Sea. Targeting consistently emphasizes naval defense contractors, shipbuilding, submarine technology research, autonomous underwater vehicles, sonar and acoustic detection systems, maritime research universities (with US-Pacific-coast institutions particularly prominent), and government maritime / fisheries / coast-guard organizations. The Accenture iDefense 'MUDCARP's Focus on Submarine Technologies' report formalized this strategic-targeting interpretation. Beyond the maritime mission, APT40 has demonstrated broad flexibility supporting Beijing's regional political objectives, targeting Cambodian election infrastructure ahead of the 2018 vote, Belt and Road Initiative partner countries, Southeast Asian governments, and Pacific Island nations including Samoa and Papua New Guinea. The March 2024 New Zealand Government / GCSB attribution of a 2021 NZ parliamentary network breach to APT40 represented the first formal NZ public attribution of a cyber intrusion to the Chinese state. The 2024 Samoan government attribution was the first-ever Pacific Island nation's public attribution of cyber attacks to APT40. Tradecraft hallmarks: (a) rapid n-day exploitation of public- facing vulnerabilities, APT40 is among the fastest-adopting actors in the public record, often weaponizing CVEs within days of disclosure (Log4Shell, ProxyLogon, Confluence, Citrix NetScaler, Barracuda ESG)

(b) compromised SOHO router and small-office device infrastructure for operational staging (paralleling Volt Typhoon's KV botnet model)

(c) ScanBox web- based reconnaissance framework deployed via watering-hole compromises.

(d) DLL side-loading with legitimately-signed Microsoft binaries.

(e) China Chopper webshells, Cobalt Strike beacons, Derusbi and PlugX backdoors.

(f) credential-harvesting via Mimikatz/LaZagne and large-scale password-spray campaigns. The July 2024 multi-government 'APT40 Tradecraft in Action' advisory provides the most current operational picture. APT40 / Leviathan / Gingham Typhoon (Microsoft's current naming) operates within the broader provincial-MSS contractor ecosystem that also includes APT10 (Tianjin), Mustang Panda, Hafnium / Silk Typhoon, and Salt Typhoon, overlapping tooling and infrastructure between these clusters is widely documented and sometimes makes precise cluster attribution challenging.

Aliases

33
apt40leviathanmudcarpkryptonite pandagadoliniumbronze mohawktemp.jumpertemp jumpertemp.periscopetemp periscopegingham typhoonfeverdreamfever dreamgreencrashgreen crashhellsingperiscopeislanddreamsisland dreamsitg09ta423red ladonjjdooratk29mss hainanmss hainan state security departmenthainan state security departmenthssdhainan xiandunhainan xiandun technologyg0065apt 40apt-40

Notable Campaigns

13
2024Samoan Government Attribution of APT40 (2024)
2024CISA et al., PRC MSS APT40 Tradecraft in Action (July 8, 2024)
2021New Zealand Parliamentary Network Breach (2021, disclosed March 2024)
2021US DOJ APT40 Indictment of Four MSS Officers (July 19, 2021)
2021CISA AA21-200A, TTPs of Indicted APT40 Actors (July 19, 2021)
2021Hafnium / Microsoft Exchange ProxyLogon Overlap (2021)
2020-2022COVID-19 Vaccine and Pharmaceutical Targeting (2020-2022)
2020GADOLINIUM, Microsoft Detecting Empires in the Cloud (September 2020)
2019FireEye APT40, Examining a China-Nexus Espionage Actor (March 2019)
2019MUDCARP Focus on Submarine Technologies (Accenture iDefense March 2019)
2018TEMP.Periscope U.S. Engineering and Maritime Industries Campaign (FireEye March 2018)
2017-2018Cambodian Election and Political Targeting (2017-2018)
2009-2026Long-Running Maritime Industry Targeting (2009-present)

Attribution & Reporting

Attributed by
US Department of JusticeFBICISANSAUS Cyber CommandUS Department of StateUK NCSCUK National Cyber Security CentreAustralian Signals Directorate (ASD)Australian Cyber Security Centre (ACSC)Australian Federal Police (AFP)Canadian Centre for Cyber Security (CCCS)Communications Security Establishment Canada (CSE)New Zealand NCSCNew Zealand Government Communications Security Bureau (GCSB)Japan NPASouth Korea NISEuropean UnionNATOFive EyesMandiantFireEyeMicrosoftCrowdStrikeProofpointSymantec / BroadcomTrend MicroKasperskyCisco TalosAccenture iDefenseSecureworks Counter Threat UnitRecorded FutureInsikt GroupSentinelOneVolexitySamoan Government
Key reporting
reportFireEye: Suspected Chinese Cyber Espionage Group (TEMP.Periscope) Targeting US Engineering and Maritime Industries (March 2018)
reportFireEye / Mandiant: APT40, Examining a China-Nexus Espionage Actor (March 2019)
reportAccenture iDefense: MUDCARP's Focus on Submarine Technologies (March 2019)
reportProofpoint: Leviathan, Espionage Actor Spearphishes Maritime and Defense Targets
reportCrowdStrike (Adam Kozy): Two Birds, One Stone Panda (August 2018)
reportMicrosoft: GADOLINIUM, Detecting Empires in the Cloud (September 2020)
reportUS DOJ Indictment: USA v. Ding Xiaoyang et al. (July 19, 2021), Four MSS Hainan Officers
reportFBI Wanted Notice: APT40, Four PRC Nationals
reportCISA / FBI / NSA AA21-200A: TTPs of Indicted APT40 Actors Associated with China's MSS Hainan State Security Department (July 2021)
reportMulti-Government Joint Statement: PRC MSS APT40 Tradecraft in Action (July 8, 2024, CISA, NSA, FBI, ACSC, NCSC-UK, CCCS, GCSB, BfV, NISC, NIS)
reportUK NCSC: UK Allies and Partners Attribute Cyber Attacks to China (July 2021)
reportAustralian Signals Directorate / ACSC: Advisory on APT40 (July 2021)
reportCommunications Security Establishment Canada (CSE): Joint Statement on PRC MSS
reportNew Zealand GCSB: Condemnation of Malicious Cyber Activity by Chinese State Actors (March 2024)
reportVolexity: APT40 (aka Leviathan) Tampers with ASPXAUTH Cookies (September 2022)
reportSecureworks CTU: Threat Profile, BRONZE MOHAWK
reportSymantec: Leviathan Espionage Targets Engineering, Maritime
reportRecorded Future: Charting China's Threat Landscape
reportEuRepoC: APT Profile, APT 40

Operational

State sponsor

People's Republic of China Ministry of State Security (MSS), Hainan State Security Department (HSSD). Operates from Haikou, Hainan Province via front company Hainan Xiandun Technology Development Company. Formally attributed via the July 19, 2021 US DOJ indictment of four MSS officers and Hainan Xiandun operator Wu Shurong, accompanied by a coordinated multi-government attribution statement.

Motivations
espionage, intelligence_gathering, intellectual_property_theft, maritime_research_collection, naval_technology_collection, submarine_technology_collection, south_china_sea_geopolitics, belt_and_road_initiative_support, regime_objectives, industrial_espionage, dual_use_technology_collection
Sectors
Regions

Detection Blind Spots

60 techniques
Across this actor’s 60 mapped techniques, the share covered by each detection layer. Low bars are where you’d be blind if this actor targeted you.
Behavioral / log (Sigma)59/60 · 98%
Analytics (MITRE CAR)36/60 · 60%
Runtime / container (Falco)5/60 · 8%
File / malware (YARA)0/60 · 0%
Network (Suricata/Snort)13/60 · 21%
Vuln scan (Nuclei)0/60 · 0%

Atomic Test Plan

30 techniques
Runnable Atomic Red Team tests covering this actor’s mapped techniques - validate your detections against this specific adversary. Cross-reference the blind spots above. For authorized lab / purple-team use. Open the full builder
Intelligence Graph · click any node to traverse
CVETechnique ActorTool Family
drag to reposition · click any node to traverse · button top-right enlarges
External lookups - second-class, for what we don’t hold ourselves
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh  ·  Open-source threat intelligence platform  ·  100+ authoritative sources  ·  Every fact traces to its origin