APT5

MITRE ATT&CK: G1023 View on attack.mitre.org

Aliases: Mulberry Typhoon, MANGANESE, BRONZE FLEETWOOD, Keyhole Panda, UNC2630, KEYHOLE PANDA, TEMP.Bottle, Poisoned Flight, APT5, TABCTENG, Backdoor-DPD, COVENANT, CYSERVICE, Bottle, Red Horus, Red Naga, Auriga, ATG48, TG-2754

First seen
2007-01-01 00:00:00
Origin
CN
Primary motivation
espionage
Sophistication
advanced
Resource level
government
Actor type
nation-state
Last IoC activity
2026-06-16 02:00:35
Profile updated
2026-07-07 12:33:34

Targeted industries: technology-and-telecommunications defense-and-aerospace

Targeted regions: country_code:us country_code:de country_code:cn

Context

APT5 is a China-based espionage actor that has been active since at least 2007 primarily targeting the telecommunications, aerospace, and defense industries throughout the U.S., Europe, and Asia. APT5 has displayed advanced tradecraft and significant interest in compromising networking devices and their underlying software including through the use of zero-day exploits.

Detection coverage

  • 12 YARA rules
  • 762 Sigma rules

Malware & tools used

  • PowerShell (attack-pattern)
  • Local Account (attack-pattern)
  • Timestomp (attack-pattern)
  • Remote Desktop Protocol (attack-pattern)
  • Log Enumeration (attack-pattern)
  • Disable or Modify Tools (attack-pattern)
  • Botnet (attack-pattern)
  • Local Data Staging (attack-pattern)
  • Compromise Host Software Binary (attack-pattern)
  • Keylogging (attack-pattern)
  • Cloud Accounts (attack-pattern)
  • Archive via Utility (attack-pattern)
  • LSASS Memory (attack-pattern)
  • Security Account Manager (attack-pattern)
  • File Deletion (attack-pattern)
  • Additional Local or Domain Groups (attack-pattern)
  • Process Discovery (attack-pattern)
  • Indicator Removal (attack-pattern)
  • Cron (attack-pattern)
  • Windows Command Shell (attack-pattern)
  • SSH (attack-pattern)
  • Process Injection (attack-pattern)
  • Web Shell (attack-pattern)
  • System Network Connections Discovery (attack-pattern)
  • Domain Accounts (attack-pattern)

Reports & references

  • Mandiant — Apt Groups (report)
  • cloud.google.com — Updated Cyber Threat Actor Naming System (report)
  • Microsoft — Rwmfii (report)
  • Mandiant — Apt Groups (report)
  • Mandiant — Rpt Southeast Asia Threat Landscape (report)
  • secureworks.com — Bronze Fleetwood (report)
  • internal-fireeye.com — Suspected Apt Actors Leverage Bypass Techniques Pulse Secure Zero Day (report)
  • Microsoft — Rw1Afyw (report)
  • raw.githubusercontent.com — Microsoftmapping (report)
  • Microsoft — Microsoft Threat Actor Naming (report)
  • MITRE ATT&CK — G1023 (report)
  • media.defense.gov — Csa Apt5 Citrixadc V1 (report)
  • web.archive.org — Rpt Southeast Asia Threat Landscape (report)
  • Mandiant — Suspected Apt Actors Leverage Bypass Techniques Pulse Secure Zero Day (report)
  • Mandiant — Updates On Chinese Apt Compromising Pulse Secure Vpn Devices (report)

Attributed from

  • SPACEHOP Activity (campaign)

External references