admin@338

MITRE ATT&CK: G0018 View on attack.mitre.org

Aliases: Admin338, Team338, MAGNESIUM, admin@338

First seen
2011-01-01 00:00:00
Origin
CN
Primary motivation
espionage
Sophistication
advanced
Resource level
government
Actor type
Espionage
Profile updated
2026-07-07 12:31:48

Targeted industries: financial-services government-and-public-sector technology-and-telecommunications

Targeted regions: country_code:us country_code:uk country_code:de

Context

admin@338 is a China-based cyber threat group. It has previously used newsworthy events as lures to deliver malware and has primarily targeted organizations involved in financial, economic, and trade policy, typically using publicly available RATs such as PoisonIvy, as well as some non-public backdoors.

Detection coverage

  • 3 YARA rules
  • 210 Sigma rules

Malware & tools used

  • Spearphishing Attachment (attack-pattern)
  • System Network Configuration Discovery (attack-pattern)
  • Match Legitimate Resource Name or Location (attack-pattern)
  • File and Directory Discovery (attack-pattern)
  • Local Groups (attack-pattern)
  • System Network Connections Discovery (attack-pattern)
  • Local Account (attack-pattern)
  • Exploitation for Client Execution (attack-pattern)
  • System Service Discovery (attack-pattern)
  • Malicious File (attack-pattern)
  • System Information Discovery (attack-pattern)
  • Windows Command Shell (attack-pattern)
  • Net (malware)
  • BUBBLEWRAP (malware)
  • ipconfig (malware)
  • LOWBALL (malware)
  • netstat (malware)
  • Systeminfo (malware)
  • PoisonIvy (malware)

Reports & references

  • Mandiant — Know Your Enemy Tracking A Rapidly Evolving Apt Actor (report)
  • Mandiant — China Based Threat (report)
  • cfr.org — Admin338 (report)
  • MITRE ATT&CK — G0018 (report)

External references