Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors Leviathan

Also known as: MUDCARP, Kryptonite Panda, Gadolinium, BRONZE MOHAWK, TEMP.Jumper, APT40, TEMP.Periscope, Gingham Typhoon, Leviathan, G0065, ATK29, TA423, Red Ladon, ITG09, ISLANDDREAMS, Samurai Panda, PLA Navy, APT4, Wisp Team, ISLAND CASTLE

Description

Leviathan is a Chinese state-sponsored cyber espionage group that has been attributed to the Ministry of State Security's (MSS) Hainan State Security Department and an affiliated front company.(Citation: CISA AA21-200A APT40 July 2021) Active since at least 2009, Leviathan has targeted the following sectors: academia, aerospace/aviation, biomedical, defense industrial base, government, healthcare, manufacturing, maritime, and transportation across the US, Canada, Australia, Europe, the Middle East, and Southeast Asia.(Citation: CISA AA21-200A APT40 July 2021)(Citation: Proofpoint Leviathan Oct 2017)(Citation: FireEye Periscope March 2018)(Citation: CISA Leviathan 2024)

Goals & Targeting

Targeted Sectors

Government
Defense
Research
Manufacturing
Transportation

AI Analysis

· 1 week ago

Executive Summary

Leviathan, also known as APT40, is a Chinese state-sponsored cyber espionage group linked to the Ministry of State Security's Hainan State Security Department. Active since at least 2009, Leviathan primarily targets government, defense, and research sectors across multiple countries, with a focus on collecting sensitive information through sophisticated cyber operations.

Goals & Targeting

Leviathan's strategic objectives align with Chinese state interests, focusing on espionage against sectors that hold critical technological, defense, and economic data. The group targets government agencies, research institutions,制造业, aerospace, maritime, and transportation industries, likely to gain access to advanced technologies, military secrets, and sensitive political information. Their targeting of multiple countries suggests a global reach with a focus on adversaries of strategic interest to China.

Enhanced Description

Leviathan is a high-sophistication threat group known for conducting state-sponsored cyber espionage activities. Originating from China, Leviathan has been active for over a decade, primarily targeting critical infrastructure and government entities in the United States, Canada, Australia, Europe, the Middle East, and Southeast Asia. The group is associated with multiple aliases, including MUDCARP, Kryptonite Panda, Gadolinium, and others. Leviathan's operations are characterized by advanced persistent threat techniques, including spear-phishing campaigns, custom malware development, and exploitation of vulnerabilities in industrial control systems. Their primary goal appears to be the theft of sensitive information for strategic and military advantage.

Key Capabilities

  • State-sponsored cyber espionage
  • Custom malware development
  • Spear-phishing campaigns
  • Vulnerability exploitation
  • Lateral movement within networks
  • Data exfiltration techniques
  • Use of legitimate tools for malicious purposes
  • Sophisticated persistence mechanisms

MITRE ATT&CK Tactics

Espionage
Exfiltration
Lateral Movement
Defense Evasion
Credential Access
Disruption
Reconnaissance

ATT&CK Techniques

T1059.003
T1055
T1566.001
T1074.001
T1584.008
T1218.010
T1197
T1047
T1027.001
T1041
T1567.002
T1203
T1140
T1091

Software / Tooling

Cobalt Strike
China Chopper
NanHaiShu
HOMEFRY
gh0st RAT
Derusbi
BADFLICK
ORZ
MURKYTOP

Campaigns & Victims

Leviathan has been involved in numerous campaigns targeting high-value assets across various industries. Their operations are known for their persistence and focus on long-term access to victim networks, allowing them to exfiltrate large volumes of sensitive data over extended periods. Notable campaign patterns include the use of spear-phishing emails with malicious attachments or links, employment of custom malware, and exploitation of zero-day vulnerabilities. Leviathan's campaigns often involve multi-stage attacks, with initial access followed by lateral movement and data collection before exfiltration.

IOC Patterns

  • Spear-phishing emails with malicious Office documents
  • C2 communications over encrypted channels or protocols
  • Use of known malware families like Cobalt Strike
  • Lateral movement within networks using tools like Posh_ssh
  • Data staging and exfiltration to external servers or cloud storage
  • Malicious scripts delivered via compromised websites

Recommended Actions

  • Implement multi-factor authentication for sensitive systems.
  • Monitor network traffic for signs of lateral movement and unusual activity.
  • Conduct regular phishing simulations to improve employee awareness.
  • Patch systems promptly to mitigate known vulnerabilities.
  • Use endpoint detection and response (EDR) solutions to detect malicious activities.
  • Segregate critical infrastructure from general network access.
  • Perform regular audits of external-facing services for potential exploitation vectors.

Suggested Tags

APT
espionage
state-sponsored
cyber espionage
defense sector

Confidence Assessment

High confidence in the assessment of Leviathan's activities due to multiple independent reports and attributions. However, some specifics about their internal structures and exact operational directives remain unclear due to limited access to classified intelligence sources.

ATT&CK Techniques

Execution
7 techniques
Persistence
4 techniques
Resource Development
8 techniques
Stealth
9 techniques

Software / Tooling

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

No IOCs linked yet.

References

  1. Accenture MUDCARP March 2019 — Accenture iDefense Unit. (2019, March 5). Mudcarp's Focus on Submarine Technologies. Retrieved August 24, 2021.
  2. Crowdstrike KRYPTONITE PANDA August 2018 — Adam Kozy. (2018, August 30). Two Birds, One Stone Panda. Retrieved August 24, 2021.
  3. Proofpoint Leviathan Oct 2017 — Axel F, Pierre T. (2017, October 16). Leviathan: Espionage actor spearphishes maritime and defense targets. Retrieved February 15, 2018.
  4. MSTIC GADOLINIUM September 2020 — Ben Koehl, Joe Hannon. (2020, September 24). Microsoft Security - Detecting Empires in the Cloud. Retrieved August 24, 2021.
  5. CISA Leviathan 2024 — CISA et al. (2024, July 8). People’s Republic of China (PRC) Ministry of State Security APT40 Tradecraft in Action. Retrieved February 3, 2025.
  6. CISA AA21-200A APT40 July 2021 — CISA. (2021, July 19). (AA21-200A) Joint Cybersecurity Advisory – Tactics, Techniques, and Procedures of Indicted APT40 Actors Associated with China’s MSS Hainan State Security Department. Retrieved August 12, 2021.
  7. FireEye Periscope March 2018 — FireEye. (2018, March 16). Suspected Chinese Cyber Espionage Group (TEMP.Periscope) Targeting U.S. Engineering and Maritime Industries. Retrieved April 11, 2018.
  8. Microsoft Threat Actor Naming July 2023 — Microsoft . (2023, July 12). How Microsoft names threat actors. Retrieved November 17, 2023.
  9. FireEye APT40 March 2019 — Plan, F., et al. (2019, March 4). APT40: Examining a China-Nexus Espionage Actor. Retrieved March 18, 2019.
  10. SecureWorks BRONZE MOHAWK n.d. — SecureWorks. (n.d.). Threat Profile - BRONZE MOHAWK. Retrieved August 24, 2021.

Intel Summary

50

Techniques

17

Tools

0

Campaigns

0

IOCs

0

Observed Data

13

Tactics

Tags

APT
Healthcare Targeting
Government Targeting
espionage
state-sponsored
cyber espionage
defense sector

Details

MITRE ID
G0065
Type
Unknown
Resource Level
Government
Primary Motivation
Espionage
Country of Origin
China (CN)
Confidence
90%
Added
May 2, 2026
STIX ID
intrusion-set--7113eaa5-ba79-4fb3-b68a-398ee9cd698e
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.