APT1

MITRE ATT&CK: G0006 View on attack.mitre.org

Aliases: Comment Crew, Comment Group, Comment Panda, COMMENT PANDA, PLA Unit 61398, Byzantine Candor, Group 3, TG-8223, Brown Fox, GIF89a, ShadyRAT, APT1

First seen
2010-01-01 00:00:00
Origin
CN
Primary motivation
espionage
Sophistication
advanced
Resource level
government
Actor type
Espionage
Last IoC activity
2026-07-22 00:38:14
Profile updated
2026-07-07 12:31:30

Targeted industries: defense-and-aerospace technology-and-telecommunications government-and-public-sector financial-services media-and-entertainment

Targeted regions: country_code:us country_code:ca country_code:au country_code:gb

Context

APT1 is a Chinese threat group that has been attributed to the 2nd Bureau of the People’s Liberation Army (PLA) General Staff Department’s (GSD) 3rd Department, commonly known by its Military Unit Cover Designator (MUCD) as Unit 61398.

Detection coverage

  • 25 YARA rules
  • 242 Sigma rules

Malware & tools used

  • LSASS Memory (attack-pattern)
  • Process Discovery (attack-pattern)
  • Data from Local System (attack-pattern)
  • Pass the Hash (attack-pattern)
  • Domains (attack-pattern)
  • Archive via Utility (attack-pattern)
  • Automated Collection (attack-pattern)
  • Remote Email Collection (attack-pattern)
  • Spearphishing Link (attack-pattern)
  • System Network Configuration Discovery (attack-pattern)
  • Local Email Collection (attack-pattern)
  • Malware (attack-pattern)
  • System Network Connections Discovery (attack-pattern)
  • Email Accounts (attack-pattern)
  • Domains (attack-pattern)
  • Match Legitimate Resource Name or Location (attack-pattern)
  • Local Account (attack-pattern)
  • Spearphishing Attachment (attack-pattern)
  • Network Share Discovery (attack-pattern)
  • Windows Command Shell (attack-pattern)
  • Tool (attack-pattern)
  • System Service Discovery (attack-pattern)
  • Remote Desktop Protocol (attack-pattern)
  • Net (malware)
  • WEBC2 (malware)

Reports & references

  • Wikipedia — Pla Unit 61398 (report)
  • Mandiant — Mandiant Apt1 Report (report)
  • cfr.org — Pla Unit 61398 (report)
  • Mandiant — Mandiant Apt1 Report (report)
  • Trend Micro — The Siesta Campaign A New Targeted Attack Awakens (report)
  • Mandiant — A Detailed Examination Of The Siesta Campaign (report)
  • McAfee — Operation Oceansalt Delivers Wave After Wave (report)
  • McAfee — Rp Operation Oceansalt (report)
  • Broadcom/Symantec — Viewdocument (report)
  • MITRE ATT&CK — G0006 (report)
  • nytimes.com — Us To Charge Chinese Workers With Cyberspying (report)
  • Mandiant — Apt Groups (report)
  • Mandiant — Cds19 Executive S08 Achievement Unlocked (report)
  • cdn0.vox-cdn.com — Crowdstrike Intelligence Report Putter Panda.Original (report)

External references