Also known as: PoisonVine, APT-Q-20, malicious actors, APT groups, hackers, Sandworm Team, Operation Cleaver, Shell Crew, WebMasters, KungFu Kittens, PinkPanther, a separate entity, APT28, VOLTZITE, for follow-on operations, Fancy Bear, Forest Blizzard, Sofacy, Pawn Storm, Sednit, STRONTIUM, Cozy Bear, Midnight Blizzard, The Dukes, Nobelium, YTTRIUM, Voodoo Bear, Seashell Blizzard, IRIDIUM, Telebots, Iron Viking, Secret Blizzard, Snake, Venomous Bear, Uroburos, Waterbug, KRYPTON, Aqua Blizzard, Primitive Bear, Shuckworm, Armageddon, Actinium, Double Dragon, Brass Typhoon, Wicked Panda, Winnti, Barium, Leviathan, Gingham Typhoon, TEMP.Periscope, TEMP.Jumper, Bronze Mohawk, Volt Typhoon, Vanguard Panda, Bronze Silhouette, DEV-0391, Salt Typhoon, GhostEmperor, FamousSparrow, HAFNIUM, Silk Typhoon, Mustang Panda, Stately Taurus, Bronze President, RedDelta, TEMP.Hex, APT35, Charming Kitten, Mint Sandstorm, Phosphorus, TA453, Yellow Garuda, MuddyWater, Mango Sandstorm, Mercury, TEMP.Zagros, Static Kitten, APT34, OilRig, Hazel Sandstorm, Crambus, Helix Kitten, TG-2633, Winnti Umbrella, BRONZE ATLAS, BRONZE MOHAWK, GADOLINIUM, KRYPTONITE PANDA, G0065, ATK29, TA423, Red Ladon, ITG09, MUDCARP, ISLANDDREAMS, ISLAND CASTLE, Parastoo, iKittens, NEWSCASTER, NewsBeef, Group 83
APT-C-01 operates under a highly compartmentalized structure that allows it to conduct multi‑phase attacks across numerous industries and geographies. Known aliases such as PoisonVine, APT-Q‑20, and Shell Crew are frequently referenced in threat reports; the actor harnesses both well‑known commercial tools (Poison Ivy, Kanbox RAT) and custom malware families, sometimes leveraging publicly disclosed CVEs (CVE‑2012‑0158, CVE‑2014‑6352, CVE‑2017‑8759). The group’s campaign repertoire includes high‑profile incidents like the Australian Parliament hack and Citrix compromise, underscoring its capability to target sophisticated, high‑value infrastructure. APT-C-01’s threat model centers on stealth, persistence, and exfiltration. Their arsenal spans Windows system modifications including scheduled tasks (T1053.005), service creation (T1543.003), and rootkits (T1014) for long‑term covert presence. Adverse actions are frequently carried out through spearphishing campaigns that deliver malicious attachments or links, often coupled with PowerShell execution (T1059.001), DNS tunneling (T1071.004), and encrypted file carriers to evade detection. The actor’s modular approach—mixing publicly available exploits, custom scripts, and supply‑chain compromises—enables rapid pivoting across sectors while maintaining a low public profile. This results in repeated, often overlapping attacks that aim to harvest strategic or proprietary data for geopolitical advantage.
Fake Social Media Account
Targeted Sectors
Targeted Countries / Regions
Executive Summary
APT-C-01, also known as PoisonVine and a host of other aliases, is a nation‑state actor that targets a wide array of sectors—including government, defense, research, maritime, and critical infrastructure—across the globe. They employ commercially available RATs, custom backdoors, and proven public exploit CVEs to establish persistent footholds and exfiltrate intelligence. The group’s operations range from spear‑phishing campaigns to supply‑chain compromises, indicating a high level of strategic intent and tactical sophistication.
Goals & Targeting
APT-C-01 appears motivated primarily by espionage objectives, focusing on acquiring intelligence about military, research, and maritime capabilities worldwide. The broad geographic footprint (China, U.S., Russia, Iran, Pakistan, Ukraine, Israel, Vietnam, Saudi Arabia, etc.) reflects a desire to gather data that can inform strategic decision‑making across competing nation‑states. Typical victims include governmental agencies, defense contractors, research institutions, and critical infrastructure operators whose data or systems provide insights into national security policy, technological advancement, and global supply chains.
Enhanced Description
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
APT-C-01 typically launches short, highly targeted attacks that transition from initial compromise via spear‑phishing or public exploit to a staged implant using custom RATs. The actor often creates multiple staging environments on compromised servers and leverages legitimate services (e.g., Microsoft Azure, Google Cloud) for C2 or exfiltration. Campaigns like the Australian Parliament hack demonstrate a capacity for sophisticated persistence mechanisms and multi‑layered evasion. Operational tempo appears moderate to high depending on target value, with repeated attempts against similar sectors across different nation‑states. The group’s broad alias list suggests that attribution can be obfuscated by merging unrelated APT operations under common nomenclature; however, shared tool families and attack vectors provide a distinguishing technical footprint.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
The intelligence is compiled primarily from public reports that reference PoisonVine and the actor’s extensive alias list. While there is strong evidence for tool usage (Poison Ivy, ZxShell), known CVEs, and spear‑phishing techniques, detailed operational timelines, exact attribution mapping across all aliases, and the full extent of supply‑chain involvement remain uncertain. The reliance on conflated group names introduces ambiguity; therefore confidence in precise capabilities is moderate, with gaps noted around specific dates, infrastructure footprints, and confirmation of recent activity.
Australian Parliament Hack
Citrix Hack
No observed data linked yet.
40
Techniques
73
Tools
2
Campaigns
40
IOCs
0
Observed Data
13
Tactics