Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors APT-C-12

Also known as: Sapphire Mushroom, Blue Mushroom, NuclearCrisis, APT groups, hackers, Sandworm Team, Operation Cleaver, Shell Crew, KungFu Kittens, PinkPanther, APT28, VOLTZITE, Fancy Bear, Forest Blizzard, Sofacy, Pawn Storm, Sednit, STRONTIUM, Cozy Bear, Midnight Blizzard, The Dukes, Nobelium, YTTRIUM, Voodoo Bear, Seashell Blizzard, IRIDIUM, Telebots, Iron Viking, Secret Blizzard, Snake, Venomous Bear, Uroburos, Waterbug, KRYPTON, Aqua Blizzard, Primitive Bear, Shuckworm, Quedagh, VOODOO BEAR, TEMP.Noble, IRON VIKING, G0034, ELECTRUM, TeleBots, Blue Echidna, FROZENBARENTS, UAC-0113, UAC-0082, APT44, DarkHalo, StellarParticle, NOBELIUM, Solar Phoenix, Group 88, Turla Team, Krypton, SIG23, MAKERSMARK, IRON HUNTER, SANDWORM RELIC, malicious actors, tracked as, WebMasters, a separate entity, for follow-on operations, Unit 61398, Armageddon, Actinium, Double Dragon, Brass Typhoon, Wicked Panda, Winnti, Barium, Leviathan, Gingham Typhoon, TEMP.Periscope, TEMP.Jumper, Bronze Mohawk, Volt Typhoon, Vanguard Panda, Bronze Silhouette, DEV-0391, Salt Typhoon, GhostEmperor, FamousSparrow, HAFNIUM, Silk Typhoon, Mustang Panda, Stately Taurus, Bronze President, RedDelta, TEMP.Hex, APT35, Charming Kitten, Mint Sandstorm, Phosphorus, TA453, Yellow Garuda, MuddyWater, Mango Sandstorm, Mercury, TEMP.Zagros, Static Kitten, APT34, OilRig, Hazel Sandstorm

Description

APT‑C‑12 is a sophisticated nation‑state actor whose operations date back to 2011. According to 360 TIC, the group has repeatedly infiltrated key units of the Chinese government, military industry, scientific research institutes, and financial services. It focuses specifically on data related to nuclear technology and advanced scientific research, leveraging custom malware development tailored for each engagement. The actor maintains an extensive digital footprint: over 670 distinct malware samples have been observed in the wild, including more than 60 specialized plugins designed for lateral movement across target networks. Its command‑and‑control network consists of upwards of 40 domains and IP addresses that support staging, data exfiltration, and remote control functions. Tactics employed by APT‑C‑12 span a wide spectrum of the ATT&CK framework—ranging from spear‑phishing via attachments or links, exploitation of public‑facing applications, supply‑chain compromises, to stealthy persistence mechanisms like rootkits and web shells. The group heavily utilizes legitimate remote‑access tools and custom backdoors to maintain long‑term access while evading detection. Operational security remains a hallmark: the actor frequently abuses compromised infrastructure (domains, VPS, servers) for acquisition and staging, and uses multi‑hop proxies to obfuscate its traffic. This combination of bespoke malware, expansive infrastructure, and diverse entry techniques allows APT‑C‑12 to conduct high‑value espionage with low visibility to traditional security controls.

Goals & Targeting

Targeted Sectors

Government
Defense
Research
Financial services
Telecommunications
Healthcare
Education
Non profit
Energy
Manufacturing
Media
Aerospace
Critical infrastructure
Information technology
Pharmaceutical
Think tank
Nuclear
Aviation
Hospitality
Legal services
Transportation
Mining
Chemical
Gaming
Retail
Maritime
Entertainment
Oil gas
Construction
Utilities

Targeted Countries / Regions

CN
US
RU
IR
IL
SA
VN
UA
AE
JP
PK
GB
IN
AU
KR
TW
TR
SG
DE
KP
BY
RO
MX
ES
PL
CA
LB
FR
NG
IT
AZ
KZ
europe

AI Analysis

Grounded in web research
· 2 days ago

Executive Summary

APT‑C‑12, also called Sapphire Mushroom or Blue Mushroom, has conducted continuous cyber espionage against Chinese defense, military and nuclear research entities since at least 2011. The group produces custom malware—including over 600 samples and 60 lateral‑movement plugins—and operates a broad C2 infrastructure with more than 40 domains and IPs. Its primary objective is to harvest technical and scientific information that supports China’s strategic interests.

Goals & Targeting

APT‑C‑12’s strategic goal is to acquire classified or proprietary information that advances Chinese nuclear research, defense development, and related scientific breakthroughs. The actor targets a broad array of sectors—government, defense, research institutions, financial services, telecommunications, healthcare, energy, aerospace, critical infrastructure, and more—to gather the technological inputs necessary for dual‑use advancements. Victims are typically high‑profile organizations with access to advanced R&D, nuclear data, or sensitive policy documents. By extracting this intelligence, APT‑C‑12 seeks to inform state policies, support weapons development, and provide a competitive edge in strategic domains.

Enhanced Description

Key Capabilities

  • Custom malware development
  • Advanced persistent infection lifecycle
  • Lateral movement via malicious plugins
  • Command & control over multiple domains/IPs
  • Spear‑phishing attachments and links
  • Exploitation of public‑facing applications
  • Supply‑chain compromise
  • Use of remote access tools (RATs)
  • Persistence through rootkits and web shells
  • Data exfiltration via web services and encrypted channels

MITRE ATT&CK Tactics

Initial Access
Execution
Persistence
Privilege Escalation
Defense Evasion
Credential Access
Discovery
Lateral Movement
Collection
Exfiltration
Command & Control

ATT&CK Techniques

T1566.001
T1566.002
T1203
T1074
T1105
T1190
T1218
T1040
T1059.003
T1087
T1003
T1014
T1574
T1090
T1505.003
T1583.001
T1583.004
T1550.001
T1562
T1546
T1189

Software / Tooling

Emissary
StrongPity
Agent.btz
Machete
Cobalt Strike
Mimikatz
PowerShell scripts
Metasploit Framework
Custom RAT backdoors
Web shell suites (e.g., Ckife, China Chopper)

Campaigns & Victims

Since 2011 APT‑C‑12 has operated with a consistent tempo of infiltration and data harvest. The actor’s campaigns tend to begin with carefully crafted spear‑phishing or exploitation of public services, followed by rapid internal pivoting using custom lateral‑movement modules. Victims are often large or mid‑size organizations in the targeted sectors; once initial compromise is achieved, APT‑C‑12 establishes multiple staging points across compromised infrastructure. Notable past operations include penetrations into Chinese nuclear research labs and defense ministries, yielding technical data that likely supported state weapons programs. The group’s sustained presence is reflected by a steady stream of malware samples and new C2 domains issued over the years.

IOC Patterns

  • Spear‑phishing with macro‑laden Office documents or malicious attachments
  • Spear‑phishing links via compromised email accounts
  • Exfiltration over web services such as Google Drive, Dropbox, Salesforce
  • Staging infrastructure on bulletproof hosting providers
  • Use of temporary domain names (e.g., TEMP.*) for command & control
  • Compromise of third‑party software supply chain
  • Deployment of web shells (Ckife, China Chopper) on compromised servers

Recommended Actions

  • Implement multi-factor authentication and least privilege controls across all critical systems, especially in defense and research environments.
  • Deploy advanced email filtering to detect and quarantine spear‑phishing links and attachments.
  • Block outbound traffic to known malicious C2 domains and IPs identified in IOC lists.
  • Regularly patch public‑facing applications and services to close exploitable vulnerabilities.
  • Segment networks to limit lateral movement and enforce micro‑segmentation between sensitive segments.
  • Conduct continuous monitoring of credential use (e.g., suspicious brute‑force or privilege escalation attempts).
  • Maintain a robust threat intelligence subscription for updates on new APT‑C‑12 malware families and domain changes.
  • Develop and routinely test an incident response plan that specifically addresses low‑visibility espionage activity.

Suggested Tags

APT
Espionage
State-sponsored
China
Nuclear Industry
Scientific Research
Defense
Government
Critical Infrastructure

Confidence Assessment

The analysis is based primarily on a 360 TIC description citing continuous operations since 2011 and Malpedia’s listing of APT‑C‑12. While the evidence confirms high‑level capabilities, there is limited publicly available corroboration for tool attribution or specific campaign details beyond the malware sample count. The extensive alias list intersects with many unrelated groups, which suggests potential misclassifications; however, the described targeting focus and domain counts provide reasonable confidence in the core threat profile. Remaining gaps include up‑to‑date IOC data and definitive evidence linking known tools to APT‑C‑12’s operations.

ATT&CK Techniques

Collection
1 technique
Discovery
1 technique
Exfiltration
1 technique
Persistence
1 technique
Privilege Escalation
1 technique

Software / Tooling

Observed Data

No observed data linked yet.

Indicators of Compromise

Domain 15 Filename 5

References

  1. attack.mitre.org — Cited by web research for: Sandworm Team
  2. docs.rapid7.com — Cited by web research for: Unit 61398
  3. cybergeodigest.com — Cited by web research for: Fancy Bear
  4. learn.microsoft.com — Cited by web research for: Jackal
  5. www.socinvestigation.com — Cited by web research for: Spear-phishing
  6. breach-hq.com — Cited by web research for: Temp.Hex
  7. https://malpedia.caad.fkie.fraunhofer.de/actor/apt-c-12 — Cited by AI analysis.
  8. 360 TIC report (as cited in threat actor data) — Cited by AI analysis.

Intel Summary

44

Techniques

77

Tools

9

Campaigns

37

IOCs

0

Observed Data

14

Tactics

Tags

Ransomware
APT
Critical Infrastructure
Backdoor / C2
Government Targeting
Espionage
State-sponsored
China
Nuclear Industry
Scientific Research
Defense
Government

Details

Type
Nation-State
Resource Level
Government
Primary Motivation
Espionage
Country of Origin
China (CN)
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.