Overview 73 indicators
Leviathan is a Chinese state-sponsored cyber espionage group that has been attributed to the Ministry of State Security's (MSS) Hainan State Security Department and an affiliated front company. Active since at least 2009, Leviathan has targeted the following sectors: academia, aerospace/aviation, biomedical, defense industrial base, government, healthcare, manufacturing, maritime, and transportation across the US, Canada, Australia, Europe, the Middle East, and Southeast Asia.
| domain | 62 | G0065-domain.txt |
| url | 7 | G0065.json |
| url_path | 4 | G0065.json |
Techniques 50 ATT&CK
Open in ATT&CK Navigator → or download the layer (50 techniques, layer 4.5)
- T1003 OS Credential Dumping
- T1003.001 LSASS Memory
- T1021.001 Remote Desktop Protocol
- T1021.004 SSH
- T1027.001 Binary Padding
- T1027.003 Steganography
- T1027.013 Encrypted/Encoded File
- T1027.015 Compression
- T1041 Exfiltration Over C2 Channel
- T1047 Windows Management Instrumentation
- T1055.001 Dynamic-link Library Injection
- T1059.001 PowerShell
- T1059.005 Visual Basic
- T1074.001 Local Data Staging
- T1074.002 Remote Data Staging
- T1078 Valid Accounts
- T1090.003 Multi-hop Proxy
- T1102.003 One-Way Communication
- T1105 Ingress Tool Transfer
- T1133 External Remote Services
- T1140 Deobfuscate/Decode Files or Information
- T1189 Drive-by Compromise
- T1190 Exploit Public-Facing Application
- T1197 BITS Jobs
- T1203 Exploitation for Client Execution
- T1204.001 Malicious Link
- T1204.002 Malicious File
- T1218.010 Regsvr32
- T1505.003 Web Shell
- T1534 Internal Spearphishing
- T1546.003 Windows Management Instrumentation Event Subscription
- T1547.001 Registry Run Keys / Startup Folder
- T1547.009 Shortcut Modification
- T1553.002 Code Signing
- T1559.002 Dynamic Data Exchange
- T1560 Archive Collected Data
- T1566.001 Spearphishing Attachment
- T1566.002 Spearphishing Link
- T1567.002 Exfiltration to Cloud Storage
- T1572 Protocol Tunneling
- T1583.001 Domains
- T1584.004 Server
- T1584.008 Network Devices
- T1585.001 Social Media Accounts
- T1585.002 Email Accounts
- T1586.001 Social Media Accounts
- T1586.002 Email Accounts
- T1587.004 Exploits
- T1589.001 Credentials
- T1595.002 Vulnerability Scanning
Software 17
- Windows Credential Editor
- China Chopper
- Derusbi
- gh0st RAT
- Net
- BLACKCOFFEE
- at
- Cobalt Strike
- Tor
- BITSAdmin
- PowerSploit
- NanHaiShu
- Orz
- HOMEFRY
- MURKYTOP
- Empire
- BADFLICK
Principal sources 16 reports
Ranked by how many of this actor's indicators each report brought in.
- 22otx.alienvault.com/pulse/61b2290ee7cb4628d56979d5
- 22us-cert.cisa.gov/ncas/alerts/aa21-200a
- 22otx.alienvault.com/pulse/60f597533e911956a673717b
- 13medium.com/@Sebdraven/apt-40-in-malaysia-61ed9c964…
- 13twitter.com/ClearskySec/status/1110941178231484417
- 13otx.alienvault.com/pulse/5e3dbad21b45e958a0d9e5a6
- 11proofpoint.com/us/blog/threat-insight/chasing-currents…
- 11virustotal.com/gui/ip-address/139.59.60.116/relations
Related groups 6
What the sources have in common — not a claim that these are the same actor. See the whole graph.
Timeline 73 indicators
Each entry is a batch of indicators that appeared upstream on one date, under the report it was filed with.
No indicator matches. Only the most recent 300 are on this page — the rest are in the JSON.
-
proofpoint.com/us/blog/threat-insight/chasing-currents… · virustotal.com/gui/ip-address/139.59.60.116/relations
domain australianmorningnews.com domain heraldsun.me domain image.australianmorningnews.com domain regionail.xyz domain theaustralian.in domain walmartsde.com url http://172.105.114.27 url_path /?cwhe18nc url_path /cwhe18nc.htm url_path /cwhe18nc.js -
github.com/ti-research-io/ti/blob/main/ioc_extende…
rninhsss.com -
otx.alienvault.com/pulse/61b2290ee7cb4628d56979d5
api.dreamsbottle.com appexistence.com bbranchs.com cankerscarcass.com cdn.aexhausts.com cm.musicandfile.com dexercisep.com duutsxlydw.com guardggg.com iherlvufjknw.com ja.iherlvufjknw.com laodailylive.com laodata.network laodiplomat.com laotranslations.com manaloguek.com musicandfile.com news.duutsxlydw.com office.duutsxlydw.com ttxs.aexhausts.com -
otx.alienvault.com/pulse/61b2290ee7cb4628d56979d5
networkslaoupdate.com news.networkslaoupdate.com -
us-cert.cisa.gov/ncas/alerts/aa21-200a · otx.alienvault.com/pulse/60f597533e911956a673717b
cnnzapmeta.com goo2k88yyh2.chickenkiller.com katy197.chickenkiller.com mail2.ignorelist.com microsql-update.info mihybb.com nmw4xhipveaca7hm.onion.link porndec143.chickenkiller.com soure7788.chickenkiller.com teledynegroup.com testdomain2019.chickenkiller.com togetno992.mooo.com tojenner97.chickenkiller.com vser.mooo.com xbug.uk.to yorkshire-espana-sa.com -
elastic.co/fr/blog/advanced-techniques-used-in-mal… · otx.alienvault.com/pulse/5efa1262602caffb4ac35148
armybar.hopto.org tomema.myddns.me -
medium.com/@Sebdraven/apt-40-in-malaysia-61ed9c964… · twitter.com/ClearskySec/status/1110941178231484417 · otx.alienvault.com/pulse/5e3dbad21b45e958a0d9e5a6
domain byfleur.myftp.org domain capitana.onthewifi.com domain dynamics.ddnsking.com domain kulkarni.bounceme.net domain thestar.serveblog.net domain vvavesltd.servebeer.com url http://139.162.44.81 url http://152.89.161.5 url http://159.65.197.248 url http://167.99.72.82 url http://195.12.50.168 url http://207.148.79.152 -
twitter.com/Vishnyak0v/status/1203986670623887361 · medium.com/@Sebdraven/apt-40-in-malaysia-61ed9c964… · twitter.com/ClearskySec/status/1110941178231484417 · otx.alienvault.com/pulse/5e3dbad21b45e958a0d9e5a6
accountsx.bounceme.net -
otx.alienvault.com/pulse/5ca740c67a9dbc78fe32f9b9 · accenture.com/t20190305T200954Z__w__/us-en/_acnmedia/… · us-cert.cisa.gov/ncas/alerts/aa21-200a · otx.alienvault.com/pulse/60f597533e911956a673717b
wsmcoff.com -
otx.alienvault.com/pulse/5ca740c67a9dbc78fe32f9b9 · accenture.com/t20190305T200954Z__w__/us-en/_acnmedia/…
eujinonline.sytes.net -
proofpoint.com/us/blog/threat-insight/chasing-currents… · virustotal.com/gui/ip-address/139.59.60.116/relations
/D2_de2o@sp0/ -
otx.alienvault.com/pulse/5ca740c67a9dbc78fe32f9b9 · accenture.com/t20190305T200954Z__w__/us-en/_acnmedia/… · us-cert.cisa.gov/ncas/alerts/aa21-200a · otx.alienvault.com/pulse/60f597533e911956a673717b · recordedfuture.com/chinese-threat-actor-tempperiscope
thyssenkrupp-marinesystems.org -
us-cert.cisa.gov/ncas/alerts/aa21-200a · otx.alienvault.com/pulse/60f597533e911956a673717b
thestar.live -
otx.alienvault.com/pulse/5ca740c67a9dbc78fe32f9b9 · accenture.com/t20190305T200954Z__w__/us-en/_acnmedia/… · us-cert.cisa.gov/ncas/alerts/aa21-200a · otx.alienvault.com/pulse/60f597533e911956a673717b · fireeye.com/blog/threat-research/2018/07/chinese-es…
chemscalere.com scsnewstoday.com -
fireeye.com/blog/threat-research/2018/07/chinese-es…
partyforumseasia.com -
us-cert.cisa.gov/ncas/alerts/aa21-200a · otx.alienvault.com/pulse/60f597533e911956a673717b · fireeye.com/blog/threat-research/2018/07/chinese-es…
mlcdailynews.com
Further reading 26
- attack.mitre.org/groups/G0065
- learn.microsoft.com/en-us/microsoft-365/security/intelligen…
- us-cert.cisa.gov/ncas/alerts/aa21-200a
- accenture.com/us-en/blogs/cyber-defense/mudcarps-focu…
- cisa.gov/news-events/cybersecurity-advisories/aa…
- crowdstrike.com/blog/two-birds-one-stone-panda
- fireeye.com/blog/threat-research/2018/03/suspected-…
- fireeye.com/blog/threat-research/2019/03/apt40-exam…
- microsoft.com/security/blog/2020/09/24/gadolinium-det…
- proofpoint.com/us/threat-insight/post/leviathan-espion…
- secureworks.com/research/threat-profiles/bronze-mohawk
- otx.alienvault.com/pulse/5ca740c67a9dbc78fe32f9b9
- twitter.com/ClearskySec/status/1110941178231484417
- virustotal.com/gui/ip-address/139.59.60.116/relations
- twitter.com/Vishnyak0v/status/1203986670623887361
- medium.com/@Sebdraven/apt-40-in-malaysia-61ed9c964…
- otx.alienvault.com/pulse/5efa1262602caffb4ac35148
- elastic.co/fr/blog/advanced-techniques-used-in-mal…
- github.com/ti-research-io/ti/blob/main/ioc_extende…
- recordedfuture.com/chinese-threat-actor-tempperiscope
- proofpoint.com/us/blog/threat-insight/chasing-currents…
- accenture.com/t20190305T200954Z__w__/us-en/_acnmedia/…
- otx.alienvault.com/pulse/60f597533e911956a673717b
- otx.alienvault.com/pulse/5e3dbad21b45e958a0d9e5a6
- fireeye.com/blog/threat-research/2018/07/chinese-es…
- otx.alienvault.com/pulse/61b2290ee7cb4628d56979d5