Cyber overview
Cyber threat actor

APT40

MSS Hainan State Security Department · active since 2009

Maritime, defense and naval research espionage in support of PRC modernization. 4 officers indicted by DOJ in 2021.

Aliases
LeviathanKryptonite PandaTEMP.PeriscopeGADOLINIUM
Primary targets
Naval R&D Maritime industry Universities Biomedical research Defense contractors

MITRE ATT&CK techniques

4 techniques mapped · click any technique ID to open the MITRE ATT&CK entry, any CVE to view its NVD record, or any citation for source reporting.

TacticTechniqueProcedureTargetsCitation
Initial AccessT1566.001
Spearphishing Attachment
Spearphishing of maritime/naval researchers with weaponized documents.
Defense, naval R&D, universitiesASD/CISA AA24-190A
Initial AccessT1190
Exploit Public-Facing Application
Rapid weaponization of newly disclosed CVEs, often exploited within hours of PoC release.
-ASD/CISA AA24-190A
Command & ControlT1090.003
Multi-hop Proxy (SOHO ORBs)
Compromised SOHO routers used as Operational Relay Boxes to mask origin traffic.
-ASD/CISA AA24-190A
ExfiltrationT1041
Exfiltration Over C2 Channel
BADFLICK and MURKYTOP backdoors used for staged exfil of research and IP.
-ASD/CISA AA24-190A

Curated incidents

  1. 2024-07-08·Defense / Maritime·Australia, US, UK
    APT40 rapid-exploitation playbook detailed by ASD/CISA

    Compromises within hours of CVE publication; SOHO routers used as ORBs.