Cyber threat actor
APT40
MSS Hainan State Security Department · active since 2009
Maritime, defense and naval research espionage in support of PRC modernization. 4 officers indicted by DOJ in 2021.
Aliases
LeviathanKryptonite PandaTEMP.PeriscopeGADOLINIUM
Primary targets
Naval R&D Maritime industry Universities Biomedical research Defense contractors
MITRE ATT&CK techniques
4 techniques mapped · click any technique ID to open the MITRE ATT&CK entry, any CVE to view its NVD record, or any citation for source reporting.
| Tactic | Technique | Procedure | Targets | Citation |
|---|---|---|---|---|
| Initial Access | T1566.001 Spearphishing Attachment | Spearphishing of maritime/naval researchers with weaponized documents. | Defense, naval R&D, universities | ASD/CISA AA24-190A |
| Initial Access | T1190 Exploit Public-Facing Application | Rapid weaponization of newly disclosed CVEs, often exploited within hours of PoC release. | - | ASD/CISA AA24-190A |
| Command & Control | T1090.003 Multi-hop Proxy (SOHO ORBs) | Compromised SOHO routers used as Operational Relay Boxes to mask origin traffic. | - | ASD/CISA AA24-190A |
| Exfiltration | T1041 Exfiltration Over C2 Channel | BADFLICK and MURKYTOP backdoors used for staged exfil of research and IP. | - | ASD/CISA AA24-190A |
Curated incidents
- 2024-07-08·Defense / Maritime·Australia, US, UKAPT40 rapid-exploitation playbook detailed by ASD/CISA
Compromises within hours of CVE publication; SOHO routers used as ORBs.