Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors APT-C-01

Also known as: PoisonVine, APT-Q-20, malicious actors, APT groups, hackers, Sandworm Team, Operation Cleaver, Shell Crew, WebMasters, KungFu Kittens, PinkPanther, a separate entity, APT28, VOLTZITE, for follow-on operations, Fancy Bear, Forest Blizzard, Sofacy, Pawn Storm, Sednit, STRONTIUM, Cozy Bear, Midnight Blizzard, The Dukes, Nobelium, YTTRIUM, Voodoo Bear, Seashell Blizzard, IRIDIUM, Telebots, Iron Viking, Secret Blizzard, Snake, Venomous Bear, Uroburos, Waterbug, KRYPTON, Aqua Blizzard, Primitive Bear, Shuckworm, Armageddon, Actinium, Double Dragon, Brass Typhoon, Wicked Panda, Winnti, Barium, Leviathan, Gingham Typhoon, TEMP.Periscope, TEMP.Jumper, Bronze Mohawk, Volt Typhoon, Vanguard Panda, Bronze Silhouette, DEV-0391, Salt Typhoon, GhostEmperor, FamousSparrow, HAFNIUM, Silk Typhoon, Mustang Panda, Stately Taurus, Bronze President, RedDelta, TEMP.Hex, APT35, Charming Kitten, Mint Sandstorm, Phosphorus, TA453, Yellow Garuda, MuddyWater, Mango Sandstorm, Mercury, TEMP.Zagros, Static Kitten, APT34, OilRig, Hazel Sandstorm, Crambus, Helix Kitten, TG-2633, Winnti Umbrella, BRONZE ATLAS, BRONZE MOHAWK, GADOLINIUM, KRYPTONITE PANDA, G0065, ATK29, TA423, Red Ladon, ITG09, MUDCARP, ISLANDDREAMS, ISLAND CASTLE, Parastoo, iKittens, NEWSCASTER, NewsBeef, Group 83

Description

APT-C-01 operates under a highly compartmentalized structure that allows it to conduct multi‑phase attacks across numerous industries and geographies. Known aliases such as PoisonVine, APT-Q‑20, and Shell Crew are frequently referenced in threat reports; the actor harnesses both well‑known commercial tools (Poison Ivy, Kanbox RAT) and custom malware families, sometimes leveraging publicly disclosed CVEs (CVE‑2012‑0158, CVE‑2014‑6352, CVE‑2017‑8759). The group’s campaign repertoire includes high‑profile incidents like the Australian Parliament hack and Citrix compromise, underscoring its capability to target sophisticated, high‑value infrastructure. APT-C-01’s threat model centers on stealth, persistence, and exfiltration. Their arsenal spans Windows system modifications including scheduled tasks (T1053.005), service creation (T1543.003), and rootkits (T1014) for long‑term covert presence. Adverse actions are frequently carried out through spearphishing campaigns that deliver malicious attachments or links, often coupled with PowerShell execution (T1059.001), DNS tunneling (T1071.004), and encrypted file carriers to evade detection. The actor’s modular approach—mixing publicly available exploits, custom scripts, and supply‑chain compromises—enables rapid pivoting across sectors while maintaining a low public profile. This results in repeated, often overlapping attacks that aim to harvest strategic or proprietary data for geopolitical advantage.

TTP Summary

Fake Social Media Account

Goals & Targeting

Targeted Sectors

Government
Research
Defense
Financial services
Telecommunications
Healthcare
Education
Non profit
Media
Energy
Manufacturing
Critical infrastructure
Aerospace
Pharmaceutical
Transportation
Information technology
Think tank
Hospitality
Aviation
Gaming
Maritime
Nuclear
Retail
Entertainment
Legal services
Mining
Chemical
Oil gas
Construction
Utilities
Technology

Targeted Countries / Regions

CN
US
RU
IR
PK
UA
IL
VN
SA
AE
IN
GB
JP
TW
AU
TR
SG
KR
DE
ES
BY
MX
KP
PL
CA
IT
RO
FR
NG
LB
AZ
KZ
europe

AI Analysis

Grounded in web research
· 2 days ago

Executive Summary

APT-C-01, also known as PoisonVine and a host of other aliases, is a nation‑state actor that targets a wide array of sectors—including government, defense, research, maritime, and critical infrastructure—across the globe. They employ commercially available RATs, custom backdoors, and proven public exploit CVEs to establish persistent footholds and exfiltrate intelligence. The group’s operations range from spear‑phishing campaigns to supply‑chain compromises, indicating a high level of strategic intent and tactical sophistication.

Goals & Targeting

APT-C-01 appears motivated primarily by espionage objectives, focusing on acquiring intelligence about military, research, and maritime capabilities worldwide. The broad geographic footprint (China, U.S., Russia, Iran, Pakistan, Ukraine, Israel, Vietnam, Saudi Arabia, etc.) reflects a desire to gather data that can inform strategic decision‑making across competing nation‑states. Typical victims include governmental agencies, defense contractors, research institutions, and critical infrastructure operators whose data or systems provide insights into national security policy, technological advancement, and global supply chains.

Enhanced Description

Key Capabilities

  • Advanced persistent presence with stealthy persistence techniques
  • Use of commercial RATs such as Poison Ivy and Kanbox
  • Exploitation of public vulnerabilities (CVE‑2012‑0158/2014/2017) for initial access
  • DNS‑based command & control channels
  • Custom exploit chain leveraging supply‑chain compromise
  • Credential dumping via tools like Mimikatz
  • Scheduled tasks and service creation for persistence
  • Evasion through encrypted, encoded payloads
  • Exfiltration over web services and cloud storage

MITRE ATT&CK Tactics

Initial Access
Execution
Persistence
Privilege Escalation
Defense Evasion
Credential Access
Command and Control
Exfiltration
Reconnaissance
Resource Development

ATT&CK Techniques

T1053.005
T1560.001
T1003
T1027.013
T1014
T1071.004
T1036.005
T1543.003
T1566.002
T1566.001
T1574.001
T1040
T1195
T1190
T1567
T1219
T1583.001
T1218
T1021
T1505.003
T1087
T1090
T1583.006
T1041
T1059.001
T1199
T1566
T1078
T1486
T1573
T1195.002
T1567.002
T1059.003
T1070.004
T1071.001
T1105
T1003.003
T1569.002
T1656

Software / Tooling

Poison Ivy
Kanbox RAT
ZxShell
Mimikatz
PlugX
Akira
Carbanak
Cobalt Strike
PowerShell scripts
Custom backdoors

Campaigns & Victims

APT-C-01 typically launches short, highly targeted attacks that transition from initial compromise via spear‑phishing or public exploit to a staged implant using custom RATs. The actor often creates multiple staging environments on compromised servers and leverages legitimate services (e.g., Microsoft Azure, Google Cloud) for C2 or exfiltration. Campaigns like the Australian Parliament hack demonstrate a capacity for sophisticated persistence mechanisms and multi‑layered evasion. Operational tempo appears moderate to high depending on target value, with repeated attempts against similar sectors across different nation‑states. The group’s broad alias list suggests that attribution can be obfuscated by merging unrelated APT operations under common nomenclature; however, shared tool families and attack vectors provide a distinguishing technical footprint.

IOC Patterns

  • Spearphishing attachments or links delivering malicious payloads
  • DNS tunneling or fast‑flux for command & control
  • Use of legitimate domains with compromised credentials as C2 points
  • Deployment of known CVE exploits via mail attachments or web portals
  • Staging servers on bulletproof hosting"],

Recommended Actions

  • Implement multi‑factor authentication on all privileged accounts and regularly rotate credentials.
  • Patch publicly disclosed vulnerabilities such as CVE‑2012‑0158, CVE‑2014‑6352, and CVE‑2017‑8759 in a timely manner.
  • Deploy endpoint detection & response (EDR) solutions to detect anomalies like unexpected PowerShell execution and scheduled tasks.
  • Monitor DNS traffic for anomalous queries or unusual TTL values indicative of tunneling attempts.
  • Train users on phishing awareness and conduct regular simulated spear‑phishing tests.
  • Segment critical infrastructure networks to limit lateral movement if an initial compromise occurs.
  • Enforce strict application whitelisting and monitor for unauthorized DLL injection or service creation.

Suggested Tags

APT
Espionage
Supply Chain Compromise
Government Targeting
Defense Sector
Critical Infrastructure
Maritime

Confidence Assessment

The intelligence is compiled primarily from public reports that reference PoisonVine and the actor’s extensive alias list. While there is strong evidence for tool usage (Poison Ivy, ZxShell), known CVEs, and spear‑phishing techniques, detailed operational timelines, exact attribution mapping across all aliases, and the full extent of supply‑chain involvement remain uncertain. The reliance on conflated group names introduces ambiguity; therefore confidence in precise capabilities is moderate, with gaps noted around specific dates, infrastructure footprints, and confirmation of recent activity.

ATT&CK Techniques

Software / Tooling

Observed Data

No observed data linked yet.

Indicators of Compromise

Domain 11 Filename 6 SHA-256 Hash 1 SHA-1 Hash 1 MD5 Hash 1

References

  1. cybergeodigest.com — Cited by web research for: Double Dragon
  2. www.picussecurity.com — Cited by web research for: T1190
  3. cloud.google.com — Cited by web research for: T1505.003
  4. www.zscaler.com — Cited by web research for: T1071.001
  5. attack.mitre.org — Cited by web research for: phishing
  6. www.socinvestigation.com — Cited by web research for: Spear-phishing emails

Intel Summary

40

Techniques

73

Tools

2

Campaigns

40

IOCs

0

Observed Data

13

Tactics

Tags

APT
Government Targeting
espionage
nation-state
government
defense
research
Espionage
Supply Chain Compromise
Defense Sector
Critical Infrastructure
Maritime

Details

MITRE ID
APT35
Type
Nation-State
Resource Level
Government
Primary Motivation
Espionage
Country of Origin
China (CN)
Confidence
70%
Added
May 4, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.