Also known as: Comment Crew, Comment Group, Comment Panda, PLA Unit 61398, TG-8223, APT1, BrownFox, Group 3, GIF89a, ShadyRAT, Shanghai Group, Byzantine Candor, Brown Fox, G0006
APT1 is a Chinese threat group that has been attributed to the 2nd Bureau of the People’s Liberation Army (PLA) General Staff Department’s (GSD) 3rd Department, commonly known by its Military Unit Cover Designator (MUCD) as Unit 61398. (Citation: Mandiant APT1)
Shady RAT; GhostNet
Targeted Sectors
Targeted Countries / Regions
Executive Summary
APT1, also known as Comment Crew, is a Chinese threat group attributed to the 2nd Bureau of the People's Liberation Army (PLA) General Staff Department's 3rd Department. The group's primary motivation is espionage, targeting government sectors in the US and China. APT1 is known for its sophisticated operations, utilizing various tools and techniques to achieve its objectives.
Goals & Targeting
APT1's strategic objectives are centered around collecting sensitive information from government agencies and organizations in the US and China. The group targets specific sectors, including government and defense, to gather intelligence on foreign policies, military operations, and economic development. APT1's typical victims are high-ranking government officials, diplomats, and military personnel, as well as private sector organizations involved in sensitive industries such as aerospace and defense. The group's targeting profile suggests a strong focus on collecting information that could be used to inform Chinese foreign policy and military strategy.
Enhanced Description
The group's activities have been extensively documented, with several reports highlighting its use of custom malware and tools, including the PoisonIvy and Seasalt remote access trojans (RATs). APT1 has also been linked to the use of legitimate software tools, such as the PsExec and Mimikatz utilities, to facilitate its operations. The group's tactics, techniques, and procedures (TTPs) are constantly evolving, with new tools and techniques being developed and deployed to evade detection and stay ahead of security measures.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
APT1's campaign patterns suggest a high level of sophistication and planning, with the group often using advanced techniques such as encryption and steganography to evade detection. The group's operations are typically characterized by a long-term presence on compromised networks, with a focus on collecting sensitive information over an extended period. APT1 has been linked to several high-profile campaigns, including the Shady RAT and GhostNet operations, which involved the compromise of numerous government and private sector organizations worldwide. The group's operational tempo suggests a strong focus on achieving its objectives, with a willingness to adapt and evolve its TTPs to stay ahead of security measures.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
The confidence level in the available data is high, based on multiple reports and analyses from reputable sources. However, there may be some information gaps regarding the group's current activities and TTPs, as well as its relationships with other threat actors. Further research and analysis are recommended to stay up-to-date with the latest developments and to improve the overall understanding of APT1's operations.
No observed data linked yet.
23
Techniques
7
Tools
2
Campaigns
5
IOCs
0
Observed Data
8
Tactics