APT1
MITRE ATT&CK: G0006 View on attack.mitre.org
Aliases: Comment Crew, Comment Group, Comment Panda, COMMENT PANDA, PLA Unit 61398, Byzantine Candor, Group 3, TG-8223, Brown Fox, GIF89a, ShadyRAT, APT1
- First seen
- 2010-01-01 00:00:00
- Origin
- CN
- Primary motivation
- espionage
- Sophistication
- advanced
- Resource level
- government
- Actor type
- Espionage
- Last IoC activity
- 2026-07-22 00:38:14
- Profile updated
- 2026-07-07 12:31:30
Targeted industries: defense-and-aerospace technology-and-telecommunications government-and-public-sector financial-services media-and-entertainment
Targeted regions: country_code:us country_code:ca country_code:au country_code:gb
Context
APT1 is a Chinese threat group that has been attributed to the 2nd Bureau of the People’s Liberation Army (PLA) General Staff Department’s (GSD) 3rd Department, commonly known by its Military Unit Cover Designator (MUCD) as Unit 61398.
Detection coverage
- 25 YARA rules
- 242 Sigma rules
Malware & tools used
- LSASS Memory (attack-pattern)
- Process Discovery (attack-pattern)
- Data from Local System (attack-pattern)
- Pass the Hash (attack-pattern)
- Domains (attack-pattern)
- Archive via Utility (attack-pattern)
- Automated Collection (attack-pattern)
- Remote Email Collection (attack-pattern)
- Spearphishing Link (attack-pattern)
- System Network Configuration Discovery (attack-pattern)
- Local Email Collection (attack-pattern)
- Malware (attack-pattern)
- System Network Connections Discovery (attack-pattern)
- Email Accounts (attack-pattern)
- Domains (attack-pattern)
- Match Legitimate Resource Name or Location (attack-pattern)
- Local Account (attack-pattern)
- Spearphishing Attachment (attack-pattern)
- Network Share Discovery (attack-pattern)
- Windows Command Shell (attack-pattern)
- Tool (attack-pattern)
- System Service Discovery (attack-pattern)
- Remote Desktop Protocol (attack-pattern)
- Net (malware)
- WEBC2 (malware)
Reports & references
- Wikipedia — Pla Unit 61398 (report)
- Mandiant — Mandiant Apt1 Report (report)
- cfr.org — Pla Unit 61398 (report)
- Mandiant — Mandiant Apt1 Report (report)
- Trend Micro — The Siesta Campaign A New Targeted Attack Awakens (report)
- Mandiant — A Detailed Examination Of The Siesta Campaign (report)
- McAfee — Operation Oceansalt Delivers Wave After Wave (report)
- McAfee — Rp Operation Oceansalt (report)
- Broadcom/Symantec — Viewdocument (report)
- MITRE ATT&CK — G0006 (report)
- nytimes.com — Us To Charge Chinese Workers With Cyberspying (report)
- Mandiant — Apt Groups (report)
- Mandiant — Cds19 Executive S08 Achievement Unlocked (report)
- cdn0.vox-cdn.com — Crowdstrike Intelligence Report Putter Panda.Original (report)
External references
- mitre-attack — G0006
- APT1
- Comment Crew
- Comment Group
- Comment Panda
- Mandiant APT1
- CrowdStrike Putter Panda
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy