APT30
MITRE ATT&CK: G0013 View on attack.mitre.org
Aliases: APT30
- Origin
- CN
- Primary motivation
- espionage
- Sophistication
- advanced
- Resource level
- government
- Actor type
- Espionage
- Last IoC activity
- 2026-06-16 02:00:35
- Profile updated
- 2026-07-07 11:46:42
Targeted industries: government-and-public-sector defense-and-aerospace media-and-entertainment technology-and-telecommunications transportation-and-logistics
Targeted regions: country_code:in country_code:th country_code:my country_code:kr
Context
APT30 is a threat group suspected to be associated with the Chinese government. While Naikon shares some characteristics with APT30, the two groups do not appear to be exact matches.
Detection coverage
- 6 YARA rules
- 46 Sigma rules
Malware & tools used
- Spearphishing Attachment (attack-pattern)
- Malicious File (attack-pattern)
- FLASHFLOOD (malware)
- NETEAGLE (malware)
- SPACESHIP (malware)
- SHIPSHAPE (malware)
- BACKSPACE (malware)
Related threat objects
- Naikon (threat-actor)
- Raspberry Typhoon (threat-actor)
Reports & references
- Mandiant — Apt Groups (report)
- cloud.google.com — Updated Cyber Threat Actor Naming System (report)
- MITRE ATT&CK — G0013 (report)
- Mandiant — Rpt Apt30 (report)
- MITRE ATT&CK — G0013 (report)
- media.kasperskycontenthub.com — Rpt Apt30 (report)
- Kaspersky — 69953 (report)