admin@338
MITRE ATT&CK: G0018 View on attack.mitre.org
Aliases: Admin338, Team338, MAGNESIUM, admin@338
- First seen
- 2011-01-01 00:00:00
- Origin
- CN
- Primary motivation
- espionage
- Sophistication
- advanced
- Resource level
- government
- Actor type
- Espionage
- Profile updated
- 2026-07-07 12:31:48
Targeted industries: financial-services government-and-public-sector technology-and-telecommunications
Targeted regions: country_code:us country_code:uk country_code:de
Context
admin@338 is a China-based cyber threat group. It has previously used newsworthy events as lures to deliver malware and has primarily targeted organizations involved in financial, economic, and trade policy, typically using publicly available RATs such as PoisonIvy, as well as some non-public backdoors.
Detection coverage
- 3 YARA rules
- 210 Sigma rules
Malware & tools used
- Spearphishing Attachment (attack-pattern)
- System Network Configuration Discovery (attack-pattern)
- Match Legitimate Resource Name or Location (attack-pattern)
- File and Directory Discovery (attack-pattern)
- Local Groups (attack-pattern)
- System Network Connections Discovery (attack-pattern)
- Local Account (attack-pattern)
- Exploitation for Client Execution (attack-pattern)
- System Service Discovery (attack-pattern)
- Malicious File (attack-pattern)
- System Information Discovery (attack-pattern)
- Windows Command Shell (attack-pattern)
- Net (malware)
- BUBBLEWRAP (malware)
- ipconfig (malware)
- LOWBALL (malware)
- netstat (malware)
- Systeminfo (malware)
- PoisonIvy (malware)
Reports & references
- Mandiant — Know Your Enemy Tracking A Rapidly Evolving Apt Actor (report)
- Mandiant — China Based Threat (report)
- cfr.org — Admin338 (report)
- MITRE ATT&CK — G0018 (report)