Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors admin@338

Also known as: Temper Panda, Admin338, Team338, admin@338, 338 Team, MAGNESIUM, G0018

Description

admin@338 is a China-based cyber threat group. It has previously used newsworthy events as lures to deliver malware and has primarily targeted organizations involved in financial, economic, and trade policy, typically using publicly available RATs such as PoisonIvy, as well as some non-public backdoors. (Citation: FireEye admin@338)

TTP Summary

Umbrella Revolution; admin@338

Goals & Targeting

Targeted Sectors

Defense
Think tank
Government

AI Analysis

· 1 week ago

Executive Summary

admin@338, also known as Temper Panda and 338 Team, is a suspected China-based cyber threat group primarily motivated by espionage. This group has targeted defense, government, and financial sectors, utilizing tools like PoisonIvy RAT. Their TTPs include spear-phishing campaigns leveraging current events, making them a persistent and evolving threat.

Goals & Targeting

admin@338 targets sectors with strategic significance, focusing on defense and government for sensitive data. They also target financial institutions and think tanks involved in policy-making, suggesting an aim to influence economic strategies and gain political advantages through espionage.

Enhanced Description

admin@338 is a cyber espionage group known for targeting defense, government, and economic institutions. They have been active since at least 2015, with their most notable campaign being 'Umbrella Revolution.' Using tactics like spear-phishing with malicious attachments (T1566.001), they deploy tools such as PoisonIvy RAT and BUBBLEWRAP backdoor. Their ability to adapt TTPs indicates a sophisticated threat actor likely linked to state-sponsored activities.

Key Capabilities

  • Spear-phishing with malicious attachments
  • Use of RATs (e.g., PoisonIvy)
  • Deployment of backdoors (BUBBLEWRAP, LOWBALL)
  • System information discovery
  • Network configuration discovery
  • Local account management

MITRE ATT&CK Tactics

Initial Access
Persistence
Credential Access
Discovery
Lateral Movement
Collection
Exfiltration

ATT&CK Techniques

T1036.005
T1204.002
T1087.001
T1566.001
T1007
T1082
T1059.003

Software / Tooling

PoisonIvy RAT
BUBBLEWRAP
LOWBALL
Windows Command Shell

Campaigns & Victims

admin@338's longest-known campaign, 'Umbrella Revolution,' occurred between 2015 and 2016. Their activities suggest a focus on long-term objectives with occasional high-profile operations, indicating persistence despite low media coverage post-2017.

IOC Patterns

  • Spear-phishing emails referencing newsworthy events
  • Malware dropped via malicious Office documents
  • Establishment of C2 communication using legitimate channels
  • Usage of known RATs and backdoors

Recommended Actions

  • Implement robust email filtering to detect spear-phishing attempts.
  • Monitor for MITRE ATT&CK techniques T1566.001 and T1059.003 in network traffic.
  • Deploy endpoint detection and response (EDR) solutions for early threat identification.
  • Conduct regular phishing simulation exercises to enhance employee awareness.

Suggested Tags

APT
espionage
malware
China
government
defense
finance

Confidence Assessment

High confidence in admin@338's existence as an espionage group, based on FireEye and other reports. Some uncertainty exists regarding their precise origin and exact attack timelines pre-2015.

ATT&CK Techniques

Discovery
7 techniques

Observed Data

No observed data linked yet.

Indicators of Compromise

No IOCs linked yet.

References

  1. FireEye admin@338 — FireEye Threat Intelligence. (2015, December 1). China-based Cyber Threat Group Uses Dropbox for Malware Communications and Targets Hong Kong Media Outlets. Retrieved December 4, 2015.

Intel Summary

12

Techniques

5

Tools

2

Campaigns

0

IOCs

0

Observed Data

4

Tactics

Tags

APT
Backdoor / C2
espionage
malware
China
government
defense
finance

Details

MITRE ID
G0018
Type
Unknown
Resource Level
Government
Primary Motivation
Espionage
Country of Origin
China (CN)
Confidence
90%
Added
May 2, 2026
STIX ID
intrusion-set--16ade1aa-0ea1-4bb7-88cc-9079df2ae756
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.