Also known as: Mulberry Typhoon, MANGANESE, BRONZE FLEETWOOD, Keyhole Panda, UNC2630, temp.bottle, Maganese, Poisoned Flight, BASALT CASTLE
APT5 is a China-based espionage actor that has been active since at least 2007 primarily targeting the telecommunications, aerospace, and defense industries throughout the U.S., Europe, and Asia. APT5 has displayed advanced tradecraft and significant interest in compromising networking devices and their underlying software including through the use of zero-day exploits.(Citation: NSA APT5 Citrix Threat Hunting December 2022)(Citation: Microsoft East Asia Threats September 2023)(Citation: Mandiant Pulse Secure Zero-Day April 2021)(Citation: Mandiant Pulse Secure Update May 2021)(Citation: FireEye Southeast Asia Threat Landscape March 2015)(Citation: Mandiant Advanced Persistent Threats)
Targeted Sectors
Targeted Countries / Regions
Executive Summary
APT5, also known as Keyhole Panda and others, is a China-based advanced persistent threat (APT) group active since at least 2007. They primarily conduct espionage activities targeting critical infrastructure, defense, technology, telecommunications, and manufacturing sectors globally, with heightened focus on Southeast Asia. APT5 employs sophisticated techniques including zero-day exploits and custom malware to compromise networks and extract sensitive information.
Goals & Targeting
APT5's primary goal is espionage, aimed at acquiring sensitive data and intellectual property from targeted industries. Their focus on critical infrastructure, defense, technology, telecommunications, and manufacturing suggests an interest in both economic and military advantage. The targeting of Southeast Asia reflects strategic interests and potential operational ease, aligning with broader Chinese geopolitical objectives.
Enhanced Description
APT5, identified by multiple aliases such as Mulberry Typhoon and Keyhole Panda, is a state-sponsored threat group originating from China. Since their inception around 2007, they have focused on espionage activities targeting key industries across the U.S., Europe, and Asia, with a particular emphasis on Southeast Asia. Their operations involve the use of advanced tactics, techniques, and procedures (TTPs), including zero-day exploits, to compromise networking devices and software. Known for their sophisticated tradecraft, APT5 has been linked to several high-profile campaigns that highlight their ability to maintain persistent access to targeted networks. The group's activities underscore a strategic focus on gathering sensitive information from critical sectors that could provide significant advantages in geopolitical contexts.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
APT5 has been involved in several long-term campaigns exploiting vulnerabilities in networking devices and software, often using persistent techniques to maintain access. Their operational model includes patient hunting for high-value targets and adapting tactics to avoid detection. Notable past operations include compromises of critical infrastructure entities, reflecting their sustained effort to gather strategic intelligence.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
Confidence in APT5's data is high, based on multiple intelligence sources and confirmed Campaign patterns. However, gaps exist regarding exact first seen and last seen dates and specific campaign operational details. Some aliases overlap, leading to potential confusion about distinct threat groups.
No campaigns linked yet.
No observed data linked yet.
No IOCs linked yet.
29
Techniques
9
Tools
0
Campaigns
0
IOCs
0
Observed Data
10
Tactics