Overview 42 indicators
APT5 is a China-based espionage actor that has been active since at least 2007 primarily targeting the telecommunications, aerospace, and defense industries throughout the U.S., Europe, and Asia. APT5 has displayed advanced tradecraft and significant interest in compromising networking devices and their underlying software including through the use of zero-day exploits.
| domain | 41 | G1023-domain.txt |
| ipv4 | 1 | G1023.json |
Techniques 29 ATT&CK
Open in ATT&CK Navigator → or download the layer (29 techniques, layer 4.5)
- T1003.001 LSASS Memory
- T1003.002 Security Account Manager
- T1021.001 Remote Desktop Protocol
- T1021.004 SSH
- T1036.005 Match Legitimate Resource Name or Location
- T1049 System Network Connections Discovery
- T1053.003 Cron
- T1055 Process Injection
- T1056.001 Keylogging
- T1057 Process Discovery
- T1059.001 PowerShell
- T1059.003 Windows Command Shell
- T1070 Indicator Removal
- T1070.003 Clear Command History
- T1070.004 File Deletion
- T1070.006 Timestomp
- T1074.001 Local Data Staging
- T1078.002 Domain Accounts
- T1078.004 Cloud Accounts
- T1083 File and Directory Discovery
- T1098.007 Additional Local or Domain Groups
- T1136.001 Local Account
- T1190 Exploit Public-Facing Application
- T1505.003 Web Shell
- T1554 Compromise Host Software Binary
- T1560.001 Archive via Utility
- T1583.005 Botnet
- T1654 Log Enumeration
- T1685 Disable or Modify Tools
Software 13
- Mimikatz
- Skeleton Key
- PoisonIvy
- gh0st RAT
- Net
- Tasklist
- netstat
- PcShare
- SLOWPULSE
- PULSECHECK
- PACEMAKER
- SLIGHTPULSE
- RAPIDPULSE
Principal sources 1 reports
Ranked by how many of this actor's indicators each report brought in.
Timeline 42 indicators
Each entry is a batch of indicators that appeared upstream on one date, under the report it was filed with.
No indicator matches. Only the most recent 300 are on this page — the rest are in the JSON.
-
media.kasperskycontenthub.com/wp-content/uploads/sites/43/2013/04/200…
domain 4jslg.diggfunny.com domain alyac.org domain bbs.edsplan.com domain bbs.ezxsoft.com domain bomuls.com domain cache.mindplat.com domain daumfan.com domain dig.edsplan.com domain diggfunny.com domain dnf.diggfunny.com domain download.bomuls.com domain duamlive.com domain edsplan.com domain expre.dyndns.tv domain ezxsoft.com domain fh.edsplan.com domain file1.nprotects.org domain finalcover.com domain fr.duamlive.com domain gl.edsplan.com domain l.finalcover.com domain mindplat.com domain n.duamlive.com domain natefan.com domain nateon.duamlive.com domain nprotects.org domain path.alyac.org domain pc.nprotects.org domain projectxz.com domain ro.diggfunny.com domain smartnet.edsplan.com domain soucesp.com domain t.finalcover.com domain text.edsplan.com domain trendmicros.net domain unix.edsplan.com domain update.alyac.org domain update.nprotects.org domain us.duamlive.com domain vn.edsplan.com domain wf.edsplan.com ipv4 116.127.121.41:8080
Further reading 10
- attack.mitre.org/groups/G1023
- learn.microsoft.com/en-us/microsoft-365/security/intelligen…
- media.defense.gov/2022/Dec/13/2003131586/-1/-1/0/CSA-APT5…
- query.prod.cms.rt.microsoft.com/cms/api/am/binary/RW1aFyW
- web.archive.org/web/20220122121143/https://www.fireeye.…
- mandiant.com/resources/blog/suspected-apt-actors-lev…
- mandiant.com/resources/blog/updates-on-chinese-apt-c…
- mandiant.com/resources/insights/apt-groups
- secureworks.com/research/threat-profiles/bronze-fleetwo…
- media.kasperskycontenthub.com/wp-content/uploads/sites/43/2013/04/200…