Also known as: Sapphire Mushroom, Blue Mushroom, NuclearCrisis, APT groups, hackers, Sandworm Team, Operation Cleaver, Shell Crew, KungFu Kittens, PinkPanther, APT28, VOLTZITE, Fancy Bear, Forest Blizzard, Sofacy, Pawn Storm, Sednit, STRONTIUM, Cozy Bear, Midnight Blizzard, The Dukes, Nobelium, YTTRIUM, Voodoo Bear, Seashell Blizzard, IRIDIUM, Telebots, Iron Viking, Secret Blizzard, Snake, Venomous Bear, Uroburos, Waterbug, KRYPTON, Aqua Blizzard, Primitive Bear, Shuckworm, Quedagh, VOODOO BEAR, TEMP.Noble, IRON VIKING, G0034, ELECTRUM, TeleBots, Blue Echidna, FROZENBARENTS, UAC-0113, UAC-0082, APT44, DarkHalo, StellarParticle, NOBELIUM, Solar Phoenix, Group 88, Turla Team, Krypton, SIG23, MAKERSMARK, IRON HUNTER, SANDWORM RELIC, malicious actors, tracked as, WebMasters, a separate entity, for follow-on operations, Unit 61398, Armageddon, Actinium, Double Dragon, Brass Typhoon, Wicked Panda, Winnti, Barium, Leviathan, Gingham Typhoon, TEMP.Periscope, TEMP.Jumper, Bronze Mohawk, Volt Typhoon, Vanguard Panda, Bronze Silhouette, DEV-0391, Salt Typhoon, GhostEmperor, FamousSparrow, HAFNIUM, Silk Typhoon, Mustang Panda, Stately Taurus, Bronze President, RedDelta, TEMP.Hex, APT35, Charming Kitten, Mint Sandstorm, Phosphorus, TA453, Yellow Garuda, MuddyWater, Mango Sandstorm, Mercury, TEMP.Zagros, Static Kitten, APT34, OilRig, Hazel Sandstorm
APT‑C‑12 is a sophisticated nation‑state actor whose operations date back to 2011. According to 360 TIC, the group has repeatedly infiltrated key units of the Chinese government, military industry, scientific research institutes, and financial services. It focuses specifically on data related to nuclear technology and advanced scientific research, leveraging custom malware development tailored for each engagement. The actor maintains an extensive digital footprint: over 670 distinct malware samples have been observed in the wild, including more than 60 specialized plugins designed for lateral movement across target networks. Its command‑and‑control network consists of upwards of 40 domains and IP addresses that support staging, data exfiltration, and remote control functions. Tactics employed by APT‑C‑12 span a wide spectrum of the ATT&CK framework—ranging from spear‑phishing via attachments or links, exploitation of public‑facing applications, supply‑chain compromises, to stealthy persistence mechanisms like rootkits and web shells. The group heavily utilizes legitimate remote‑access tools and custom backdoors to maintain long‑term access while evading detection. Operational security remains a hallmark: the actor frequently abuses compromised infrastructure (domains, VPS, servers) for acquisition and staging, and uses multi‑hop proxies to obfuscate its traffic. This combination of bespoke malware, expansive infrastructure, and diverse entry techniques allows APT‑C‑12 to conduct high‑value espionage with low visibility to traditional security controls.
Targeted Sectors
Targeted Countries / Regions
Executive Summary
APT‑C‑12, also called Sapphire Mushroom or Blue Mushroom, has conducted continuous cyber espionage against Chinese defense, military and nuclear research entities since at least 2011. The group produces custom malware—including over 600 samples and 60 lateral‑movement plugins—and operates a broad C2 infrastructure with more than 40 domains and IPs. Its primary objective is to harvest technical and scientific information that supports China’s strategic interests.
Goals & Targeting
APT‑C‑12’s strategic goal is to acquire classified or proprietary information that advances Chinese nuclear research, defense development, and related scientific breakthroughs. The actor targets a broad array of sectors—government, defense, research institutions, financial services, telecommunications, healthcare, energy, aerospace, critical infrastructure, and more—to gather the technological inputs necessary for dual‑use advancements. Victims are typically high‑profile organizations with access to advanced R&D, nuclear data, or sensitive policy documents. By extracting this intelligence, APT‑C‑12 seeks to inform state policies, support weapons development, and provide a competitive edge in strategic domains.
Enhanced Description
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
Since 2011 APT‑C‑12 has operated with a consistent tempo of infiltration and data harvest. The actor’s campaigns tend to begin with carefully crafted spear‑phishing or exploitation of public services, followed by rapid internal pivoting using custom lateral‑movement modules. Victims are often large or mid‑size organizations in the targeted sectors; once initial compromise is achieved, APT‑C‑12 establishes multiple staging points across compromised infrastructure. Notable past operations include penetrations into Chinese nuclear research labs and defense ministries, yielding technical data that likely supported state weapons programs. The group’s sustained presence is reflected by a steady stream of malware samples and new C2 domains issued over the years.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
The analysis is based primarily on a 360 TIC description citing continuous operations since 2011 and Malpedia’s listing of APT‑C‑12. While the evidence confirms high‑level capabilities, there is limited publicly available corroboration for tool attribution or specific campaign details beyond the malware sample count. The extensive alias list intersects with many unrelated groups, which suggests potential misclassifications; however, the described targeting focus and domain counts provide reasonable confidence in the core threat profile. Remaining gaps include up‑to‑date IOC data and definitive evidence linking known tools to APT‑C‑12’s operations.
Satellite Turla
Epic Turla
The 'Penquin' Turla
Witchcoven
RUAG hack
Mosquito
Moonlight Maze
Australian Parliament Hack
Citrix Hack
No observed data linked yet.
44
Techniques
77
Tools
9
Campaigns
37
IOCs
0
Observed Data
14
Tactics