Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started

Also known as: Comment Crew, Comment Group, Comment Panda, PLA Unit 61398, TG-8223, APT1, BrownFox, Group 3, GIF89a, ShadyRAT, Shanghai Group, Byzantine Candor, Brown Fox, G0006

Description

APT1 is a Chinese threat group that has been attributed to the 2nd Bureau of the People’s Liberation Army (PLA) General Staff Department’s (GSD) 3rd Department, commonly known by its Military Unit Cover Designator (MUCD) as Unit 61398. (Citation: Mandiant APT1)

TTP Summary

Shady RAT; GhostNet

Goals & Targeting

Targeted Sectors

Government

Targeted Countries / Regions

US
CN

AI Analysis

· 2 months ago

Executive Summary

APT1, also known as Comment Crew, is a Chinese threat group attributed to the 2nd Bureau of the People's Liberation Army (PLA) General Staff Department's 3rd Department. The group's primary motivation is espionage, targeting government sectors in the US and China. APT1 is known for its sophisticated operations, utilizing various tools and techniques to achieve its objectives.

Goals & Targeting

APT1's strategic objectives are centered around collecting sensitive information from government agencies and organizations in the US and China. The group targets specific sectors, including government and defense, to gather intelligence on foreign policies, military operations, and economic development. APT1's typical victims are high-ranking government officials, diplomats, and military personnel, as well as private sector organizations involved in sensitive industries such as aerospace and defense. The group's targeting profile suggests a strong focus on collecting information that could be used to inform Chinese foreign policy and military strategy.

Enhanced Description

The group's activities have been extensively documented, with several reports highlighting its use of custom malware and tools, including the PoisonIvy and Seasalt remote access trojans (RATs). APT1 has also been linked to the use of legitimate software tools, such as the PsExec and Mimikatz utilities, to facilitate its operations. The group's tactics, techniques, and procedures (TTPs) are constantly evolving, with new tools and techniques being developed and deployed to evade detection and stay ahead of security measures.

Key Capabilities

  • Custom malware development
  • Spear-phishing campaigns
  • Vulnerability exploitation
  • Encryption and steganography
  • Advanced persistent threat (APT) operations

MITRE ATT&CK Tactics

Initial Access
Execution
Persistence
Privilege Escalation
Defense Evasion
Credential Access
Discovery
Lateral Movement
Collection
Command and Control

ATT&CK Techniques

T1059.003
T1055
T1566.001
T1566.002
T1007
T1005
T1114.001
T1114.002
T1036.005
T1584.001
T1583.001
T1585.002
T1588.001
T1588.002

Software / Tooling

PoisonIvy
Seasalt
WEBC2
CALENDAR
PsExec
Mimikatz
gsecdump
Cachedump

Campaigns & Victims

APT1's campaign patterns suggest a high level of sophistication and planning, with the group often using advanced techniques such as encryption and steganography to evade detection. The group's operations are typically characterized by a long-term presence on compromised networks, with a focus on collecting sensitive information over an extended period. APT1 has been linked to several high-profile campaigns, including the Shady RAT and GhostNet operations, which involved the compromise of numerous government and private sector organizations worldwide. The group's operational tempo suggests a strong focus on achieving its objectives, with a willingness to adapt and evolve its TTPs to stay ahead of security measures.

IOC Patterns

  • Spear-phishing with macro-laced Office documents
  • C2 over DNS using fast-flux
  • Staging infrastructure on bulletproof hosting
  • Use of custom malware and tools
  • Exploitation of vulnerabilities in software applications

Recommended Actions

  • Implement robust security measures, including firewalls, intrusion detection systems, and anti-virus software
  • Conduct regular security audits and vulnerability assessments
  • Provide training and awareness programs for employees on phishing and social engineering attacks
  • Implement a incident response plan to quickly respond to security incidents
  • Consider implementing a threat intelligence platform to stay informed about emerging threats

Suggested Tags

APT
Espionage
Government
China
US

Confidence Assessment

The confidence level in the available data is high, based on multiple reports and analyses from reputable sources. However, there may be some information gaps regarding the group's current activities and TTPs, as well as its relationships with other threat actors. Further research and analysis are recommended to stay up-to-date with the latest developments and to improve the overall understanding of APT1's operations.

ATT&CK Techniques

Discovery
6 techniques

Campaigns / Victims

Observed Data

No observed data linked yet.

References

  1. Mandiant APT1 — Mandiant. (n.d.). APT1 Exposing One of China’s Cyber Espionage Units. Retrieved July 18, 2016.
  2. CrowdStrike Putter Panda — Crowdstrike Global Intelligence Team. (2014, June 9). CrowdStrike Intelligence Report: Putter Panda. Retrieved January 22, 2016.

Intel Summary

23

Techniques

7

Tools

2

Campaigns

5

IOCs

0

Observed Data

8

Tactics

Tags

APT
Government Targeting
Espionage
Government
China
US

Details

MITRE ID
G0006
Type
Unknown
Resource Level
Government
Primary Motivation
Espionage
Country of Origin
China (CN)
Confidence
90%
Added
May 2, 2026
STIX ID
intrusion-set--6a2e693f-24e5-451a-9f88-b36a108e5662
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.