Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started

Also known as: Mulberry Typhoon, MANGANESE, BRONZE FLEETWOOD, Keyhole Panda, UNC2630, temp.bottle, Maganese, Poisoned Flight, BASALT CASTLE

Description

APT5 is a China-based espionage actor that has been active since at least 2007 primarily targeting the telecommunications, aerospace, and defense industries throughout the U.S., Europe, and Asia. APT5 has displayed advanced tradecraft and significant interest in compromising networking devices and their underlying software including through the use of zero-day exploits.(Citation: NSA APT5 Citrix Threat Hunting December 2022)(Citation: Microsoft East Asia Threats September 2023)(Citation: Mandiant Pulse Secure Zero-Day April 2021)(Citation: Mandiant Pulse Secure Update May 2021)(Citation: FireEye Southeast Asia Threat Landscape March 2015)(Citation: Mandiant Advanced Persistent Threats)

Goals & Targeting

Targeted Sectors

Critical infrastructure
Defense
Technology
Telecommunications
Manufacturing

Targeted Countries / Regions

southeast_asia

AI Analysis

· 1 week ago

Executive Summary

APT5, also known as Keyhole Panda and others, is a China-based advanced persistent threat (APT) group active since at least 2007. They primarily conduct espionage activities targeting critical infrastructure, defense, technology, telecommunications, and manufacturing sectors globally, with heightened focus on Southeast Asia. APT5 employs sophisticated techniques including zero-day exploits and custom malware to compromise networks and extract sensitive information.

Goals & Targeting

APT5's primary goal is espionage, aimed at acquiring sensitive data and intellectual property from targeted industries. Their focus on critical infrastructure, defense, technology, telecommunications, and manufacturing suggests an interest in both economic and military advantage. The targeting of Southeast Asia reflects strategic interests and potential operational ease, aligning with broader Chinese geopolitical objectives.

Enhanced Description

APT5, identified by multiple aliases such as Mulberry Typhoon and Keyhole Panda, is a state-sponsored threat group originating from China. Since their inception around 2007, they have focused on espionage activities targeting key industries across the U.S., Europe, and Asia, with a particular emphasis on Southeast Asia. Their operations involve the use of advanced tactics, techniques, and procedures (TTPs), including zero-day exploits, to compromise networking devices and software. Known for their sophisticated tradecraft, APT5 has been linked to several high-profile campaigns that highlight their ability to maintain persistent access to targeted networks. The group's activities underscore a strategic focus on gathering sensitive information from critical sectors that could provide significant advantages in geopolitical contexts.

Key Capabilities

  • Use of zero-day exploits
  • deployment of custom malware (e.g., gh0st RAT)
  • Advanced persistence techniques
  • Sophisticated network traffic analysis
  • Web shell usage for long-term access

MITRE ATT&CK Tactics

Discovery
Credential Access
Defense Evasion
Lateral Movement
Collection
Exfiltration
Impact

ATT&CK Techniques

T1560.001
T1056.001
T1074.001
T1036.005
T1021.004
T1583.005
T1055
T1190
T1070.006
T1505.003
T1053.003
T1078.002
T1059.001
T1059.003
T1049
T1685

Software / Tooling

PACEMAKER
RAPIDPULSE
gh0st RAT
Skeleton Key
SLOWPULSE
POisonIvy
PULSECHECK

Campaigns & Victims

APT5 has been involved in several long-term campaigns exploiting vulnerabilities in networking devices and software, often using persistent techniques to maintain access. Their operational model includes patient hunting for high-value targets and adapting tactics to avoid detection. Notable past operations include compromises of critical infrastructure entities, reflecting their sustained effort to gather strategic intelligence.

IOC Patterns

  • Spear-phishing emails with malicious attachments
  • Malicious scripts executed via PowerShell or CMD
  • Anomalies in network traffic using protocols like SSH or RDP
  • Presence of custom malware binaries on systems
  • Web shell activity indicative of long-term access

Recommended Actions

  • Implement robust patch management to address zero-day exploits
  • Monitor for known TTPs and mitre techniques linked to APT5
  • Deploy network visibility tools to detect anomalies in protocols like SSH or RDP
  • Conduct regular red teaming exercises to test defense mechanisms
  • Educate users on phishing awareness to mitigate spear-phishing attempts

Suggested Tags

APT
espionage
nation-state
China
Southeast_Asia

Confidence Assessment

Confidence in APT5's data is high, based on multiple intelligence sources and confirmed Campaign patterns. However, gaps exist regarding exact first seen and last seen dates and specific campaign operational details. Some aliases overlap, leading to potential confusion about distinct threat groups.

ATT&CK Techniques

Persistence
4 techniques
Stealth
8 techniques

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

No IOCs linked yet.

References

  1. FireEye Southeast Asia Threat Landscape March 2015 — FireEye. (2015, March). SOUTHEAST ASIA: AN EVOLVING CYBER THREAT LANDSCAPE. Retrieved February 5, 2024.
  2. Mandiant Advanced Persistent Threats — Mandiant. (n.d.). Advanced Persistent Threats (APTs). Retrieved February 14, 2024.
  3. Microsoft Threat Actor Naming July 2023 — Microsoft . (2023, July 12). How Microsoft names threat actors. Retrieved November 17, 2023.
  4. Microsoft East Asia Threats September 2023 — Microsoft Threat Intelligence. (2023, September). Digital threats from East Asia increase in breadth and effectiveness. Retrieved February 5, 2024.
  5. NSA APT5 Citrix Threat Hunting December 2022 — National Security Agency. (2022, December). APT5: Citrix ADC Threat Hunting Guidance. Retrieved February 5, 2024.
  6. Mandiant Pulse Secure Zero-Day April 2021 — Perez, D. et al. (2021, April 20). Check Your Pulse: Suspected APT Actors Leverage Authentication Bypass Techniques and Pulse Secure Zero-Day. Retrieved February 5, 2024.
  7. Mandiant Pulse Secure Update May 2021 — Perez, D. et al. (2021, May 27). Re-Checking Your Pulse: Updates on Chinese APT Actors Compromising Pulse Secure VPN Devices. Retrieved February 5, 2024.
  8. Secureworks BRONZE FLEETWOOD Profile — Secureworks CTU. (n.d.). BRONZE FLEETWOOD. Retrieved February 5, 2024.

Intel Summary

29

Techniques

9

Tools

0

Campaigns

0

IOCs

0

Observed Data

10

Tactics

Tags

APT
Zero-Day Exploitation
espionage
nation-state
China
Southeast_Asia

Details

MITRE ID
G1023
Type
Unknown
Resource Level
Government
Primary Motivation
Espionage
Country of Origin
China (CN)
Confidence
90%
Added
May 2, 2026
STIX ID
intrusion-set--c1aab4c9-4c34-4f4f-8541-d529e46a07f9
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.