🇨🇳

Safe

APT Group Information theft and espionage ETDA ✓

Also Known As

No alias recorded

Target Countries 48

Countries highlighted in red

United Arab Emirates Australia Bangladesh Bulgaria Brazil Canada Switzerland China Czech Republic Germany Algeria Egypt Spain Finland France United Kingdom Hungary Indonesia Israel India Islamic Republic of Iran Italy Jamaica Japan Kenya Republic of Korea Mongolia Mexico Malaysia Nigeria Netherlands Nepal New Zealand Philippines Pakistan Romania Serbia Russian Federation Saudi Arabia Singapore Senegal South Sudan Syrian Arab Republic Thailand Province of China Taiwan Ukraine United States South Africa

Sectors Targeted

National Security and International Affairs 928110 Remediation and Other Waste Management Services 5629 Grantmaking and Giving Services 8132 Mining, Quarrying, and Oil and Gas Extraction 21 Commercial Banking 52211 Elementary and Secondary Schools 6111 Religious, Grantmaking, Civic, Professional, and Similar Organizations 813 Finance and Insurance 52 Insurance Carriers and Related Activities 524 Research and Development in the Social Sciences and Humanities 54172 NGOs Human Resources Consulting Services 541612 Real Estate 531 Personal Care Services 8121 Motor Vehicle Manufacturing 3361 Arts, Entertainment, and Recreation 71 Educational Support Services 6117 Independent Artists, Writers, and Performers 7115 Education Data Processing, Hosting, and Related Services 51821 Administrative and Support and Waste Management and Remediation Services 56 Performing Arts Companies 7111 Hospitals 622 Computer Systems Design Services 541512 Offices of Lawyers 541110 Telecommunications 517 Advertising Agencies 54181 Pharmaceutical and Medicine Manufacturing 32541 Media Audio and Video Equipment Manufacturing 33431 Newspaper Publishers 51111 Software Publishers 51121 Administrative and Support Services 561 Spectator Sports 7112 Civic and Social Organizations 8134 Chemical Manufacturing 325 Information 51 Oil and Gas Extraction 211 Public Administration 92 Freight Transportation Arrangement 48851 Technology Publishing Industries (except Internet) 511 Educational Services 611 Automobile Dealers 4411 Aircraft Manufacturing 336411 Management Consulting Services 54161 Professional, Scientific, and Technical Services 54 Truck Transportation 484 Justice, Public Order, and Safety Activities 9221 Air Transportation 481 Real Estate and Rental and Leasing 53 Colleges, Universities, and Professional Schools 6113 Convention and Trade Show Organizers 56192 Health Care and Social Assistance 62 Business Schools and Computer and Management Training 6114 National Security and International Affairs 9281 Administration of Human Resource Programs 9231 Internet Publishing and Broadcasting and Web Search Portals 51913 Public Relations Agencies 54182 Outpatient Care Centers 6214 Jewelry Stores 44831 Periodical Publishers 51112 Individual and Family Services 6241 Government Computer Systems Design and Related Services 54151 Promoters of Performing Arts, Sports, and Similar Events 7113 Construction 23 NAICS:44 44 Space Research and Technology 927 Other Amusement and Recreation Industries 7139 Other Services (except Public Administration) 81 Computer Systems Design and Related Services 5415 Educational Services 61

Details

Origin 🇨🇳 CN
Last Updated 11 May 2024

MITRE ATT&CK 32

T1003 - OS Credential Dumping T1027 - Obfuscated Files or Information T1041 - Exfiltration Over C2 Channel T1059 - Command and Scripting Interpreter T1059.003 T1071 - Application Layer Protocol T1071.001 T1078 - Valid Accounts T1082 - System Information Discovery T1087 - Account Discovery T1105 - Ingress Tool Transfer T1115 - Clipboard Data T1140 - Deobfuscate/Decode Files or Information T1195 - Supply Chain Compromise T1199 - Trusted Relationship T1204 - User Execution T1498.001 T1499.004 T1539 T1543 - Create or Modify System Process T1550 - Use Alternate Authentication Material T1552 - Unsecured Credentials T1552.006 T1553 - Subvert Trust Controls T1555 - Credentials from Password Stores T1556 T1566 - Phishing T1566.001 T1578 - Modify Cloud Compute Infrastructure T1580 - Cloud Infrastructure Discovery T1588 - Obtain Capabilities T1609 - Container Administration Command

Related Zero-Days

No zero-day CVE linked to this actor