APT5
MITRE ATT&CK: G1023 View on attack.mitre.org
Aliases: Mulberry Typhoon, MANGANESE, BRONZE FLEETWOOD, Keyhole Panda, UNC2630, KEYHOLE PANDA, TEMP.Bottle, Poisoned Flight, APT5, TABCTENG, Backdoor-DPD, COVENANT, CYSERVICE, Bottle, Red Horus, Red Naga, Auriga, ATG48, TG-2754
- First seen
- 2007-01-01 00:00:00
- Origin
- CN
- Primary motivation
- espionage
- Sophistication
- advanced
- Resource level
- government
- Actor type
- nation-state
- Last IoC activity
- 2026-06-16 02:00:35
- Profile updated
- 2026-07-07 12:33:34
Targeted industries: technology-and-telecommunications defense-and-aerospace
Targeted regions: country_code:us country_code:de country_code:cn
Context
APT5 is a China-based espionage actor that has been active since at least 2007 primarily targeting the telecommunications, aerospace, and defense industries throughout the U.S., Europe, and Asia. APT5 has displayed advanced tradecraft and significant interest in compromising networking devices and their underlying software including through the use of zero-day exploits.
Detection coverage
- 12 YARA rules
- 762 Sigma rules
Malware & tools used
- PowerShell (attack-pattern)
- Local Account (attack-pattern)
- Timestomp (attack-pattern)
- Remote Desktop Protocol (attack-pattern)
- Log Enumeration (attack-pattern)
- Disable or Modify Tools (attack-pattern)
- Botnet (attack-pattern)
- Local Data Staging (attack-pattern)
- Compromise Host Software Binary (attack-pattern)
- Keylogging (attack-pattern)
- Cloud Accounts (attack-pattern)
- Archive via Utility (attack-pattern)
- LSASS Memory (attack-pattern)
- Security Account Manager (attack-pattern)
- File Deletion (attack-pattern)
- Additional Local or Domain Groups (attack-pattern)
- Process Discovery (attack-pattern)
- Indicator Removal (attack-pattern)
- Cron (attack-pattern)
- Windows Command Shell (attack-pattern)
- SSH (attack-pattern)
- Process Injection (attack-pattern)
- Web Shell (attack-pattern)
- System Network Connections Discovery (attack-pattern)
- Domain Accounts (attack-pattern)
Reports & references
- Mandiant — Apt Groups (report)
- cloud.google.com — Updated Cyber Threat Actor Naming System (report)
- Microsoft — Rwmfii (report)
- Mandiant — Apt Groups (report)
- Mandiant — Rpt Southeast Asia Threat Landscape (report)
- secureworks.com — Bronze Fleetwood (report)
- internal-fireeye.com — Suspected Apt Actors Leverage Bypass Techniques Pulse Secure Zero Day (report)
- Microsoft — Rw1Afyw (report)
- raw.githubusercontent.com — Microsoftmapping (report)
- Microsoft — Microsoft Threat Actor Naming (report)
- MITRE ATT&CK — G1023 (report)
- media.defense.gov — Csa Apt5 Citrixadc V1 (report)
- web.archive.org — Rpt Southeast Asia Threat Landscape (report)
- Mandiant — Suspected Apt Actors Leverage Bypass Techniques Pulse Secure Zero Day (report)
- Mandiant — Updates On Chinese Apt Compromising Pulse Secure Vpn Devices (report)
Attributed from
- SPACEHOP Activity (campaign)
External references
- mitre-attack — G1023
- Mulberry Typhoon
- MANGANESE
- Keyhole Panda
- UNC2630
- BRONZE FLEETWOOD
- FireEye Southeast Asia Threat Landscape March 2015
- Mandiant Advanced Persistent Threats
- Microsoft Threat Actor Naming July 2023
- Microsoft East Asia Threats September 2023
- NSA APT5 Citrix Threat Hunting December 2022
- Mandiant Pulse Secure Zero-Day April 2021
- Mandiant Pulse Secure Update May 2021
- Secureworks BRONZE FLEETWOOD Profile
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy