Also known as: MUDCARP, Kryptonite Panda, Gadolinium, BRONZE MOHAWK, TEMP.Jumper, APT40, TEMP.Periscope, Gingham Typhoon, Leviathan, G0065, ATK29, TA423, Red Ladon, ITG09, ISLANDDREAMS, Samurai Panda, PLA Navy, APT4, Wisp Team, ISLAND CASTLE
Leviathan is a Chinese state-sponsored cyber espionage group that has been attributed to the Ministry of State Security's (MSS) Hainan State Security Department and an affiliated front company.(Citation: CISA AA21-200A APT40 July 2021) Active since at least 2009, Leviathan has targeted the following sectors: academia, aerospace/aviation, biomedical, defense industrial base, government, healthcare, manufacturing, maritime, and transportation across the US, Canada, Australia, Europe, the Middle East, and Southeast Asia.(Citation: CISA AA21-200A APT40 July 2021)(Citation: Proofpoint Leviathan Oct 2017)(Citation: FireEye Periscope March 2018)(Citation: CISA Leviathan 2024)
Targeted Sectors
Executive Summary
Leviathan, also known as APT40, is a Chinese state-sponsored cyber espionage group linked to the Ministry of State Security's Hainan State Security Department. Active since at least 2009, Leviathan primarily targets government, defense, and research sectors across multiple countries, with a focus on collecting sensitive information through sophisticated cyber operations.
Goals & Targeting
Leviathan's strategic objectives align with Chinese state interests, focusing on espionage against sectors that hold critical technological, defense, and economic data. The group targets government agencies, research institutions,制造业, aerospace, maritime, and transportation industries, likely to gain access to advanced technologies, military secrets, and sensitive political information. Their targeting of multiple countries suggests a global reach with a focus on adversaries of strategic interest to China.
Enhanced Description
Leviathan is a high-sophistication threat group known for conducting state-sponsored cyber espionage activities. Originating from China, Leviathan has been active for over a decade, primarily targeting critical infrastructure and government entities in the United States, Canada, Australia, Europe, the Middle East, and Southeast Asia. The group is associated with multiple aliases, including MUDCARP, Kryptonite Panda, Gadolinium, and others. Leviathan's operations are characterized by advanced persistent threat techniques, including spear-phishing campaigns, custom malware development, and exploitation of vulnerabilities in industrial control systems. Their primary goal appears to be the theft of sensitive information for strategic and military advantage.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
Leviathan has been involved in numerous campaigns targeting high-value assets across various industries. Their operations are known for their persistence and focus on long-term access to victim networks, allowing them to exfiltrate large volumes of sensitive data over extended periods. Notable campaign patterns include the use of spear-phishing emails with malicious attachments or links, employment of custom malware, and exploitation of zero-day vulnerabilities. Leviathan's campaigns often involve multi-stage attacks, with initial access followed by lateral movement and data collection before exfiltration.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
High confidence in the assessment of Leviathan's activities due to multiple independent reports and attributions. However, some specifics about their internal structures and exact operational directives remain unclear due to limited access to classified intelligence sources.
No campaigns linked yet.
No observed data linked yet.
No IOCs linked yet.
50
Techniques
17
Tools
0
Campaigns
0
IOCs
0
Observed Data
13
Tactics