Also known as: G0013, ISTHMUS CASTLE
APT30 is a threat group suspected to be associated with the Chinese government. While Naikon shares some characteristics with APT30, the two groups do not appear to be exact matches.(Citation: FireEye APT30)(Citation: Baumgartner Golovkin Naikon 2015)
Targeted Sectors
Executive Summary
APT30 is a sophisticated threat group suspected to be associated with the Chinese government, targeting government sectors with a primary motivation that remains unclear. Their tactics, techniques, and procedures (TTPs) are characterized by the use of custom malware and spear-phishing attacks. Organizations in the government sector should be aware of the potential threat posed by APT30.
Goals & Targeting
APT30's strategic objectives appear to be focused on targeting government sectors, potentially for espionage or intelligence gathering purposes. The group's targeting of government targets suggests a high level of interest in sensitive information and a potential desire to influence or disrupt government activities. Typical victims of APT30 attacks are likely to be government agencies or organizations with sensitive information, although the group's motivations and targeting profile are not yet fully understood.
Enhanced Description
While the exact nature of APT30's relationship with the Chinese government is unclear, the group's targeting of government sectors and use of custom malware suggest a high level of sophistication and resources. The group's TTPs have been observed to be similar to those used by other Chinese threat groups, but APT30's unique characteristics and motivations set it apart from other groups.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
APT30's campaign patterns are not yet fully understood, but the group appears to be highly targeted and focused on specific government sectors. The group's operational tempo is likely to be moderate to high, with a focus on achieving specific objectives and gathering sensitive information. Notable past operations have included attacks on government agencies and organizations with sensitive information, although the exact scope and impact of these attacks are not yet fully understood.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
The confidence level in the available data on APT30 is moderate, with some information gaps existing regarding the group's motivations, goals, and relationships with other threat groups. Further research and analysis are needed to fully understand the scope and impact of APT30's activities.
Naikon
No observed data linked yet.
No IOCs linked yet.
2
Techniques
5
Tools
1
Campaigns
0
IOCs
0
Observed Data
2
Tactics