🇨🇳

Leviathan

APT Group Information theft and espionage 16 zero-day CVEs ETDA ✓

Also Known As 15 names

ATK29 BRONZE MOHAWK G0065 GADOLINIUM Gingham Typhoon ISLANDDREAMS ITG09 KRYPTONITE PANDA APT40 MUDCARP Red Ladon TA423 TEMP.Jumper TEMP.Periscope APT 40

Target Countries 21

Countries highlighted in red

Australia Belgium Burkina Faso Switzerland Chile Germany France Hong Kong Indonesia Cambodia Myanmar Malaysia Norway New Zealand Philippines Saudi Arabia Thailand United States Vietnam South Africa Zambia

Details

Origin 🇨🇳 CN
Last Updated 01 Jun 2022

Malware Families 14

scanbox
dadstache
dreambot
cactustorch
snifula
ldr4
airbreak
saigon
grillmark
lazycat
vawtrak
sedll
lunchmoney
gozi

MITRE ATT&CK 173

T1001 T1003 T1003.001 T1005 T1007 T1008 T1011 T1012 T1014 T1016 T1018 T1021 T1021.001 T1021.002 T1021.004 T1027 - Obfuscated Files or Information T1027.001 T1027.003 T1027.013 T1027.015 T1029 T1030 T1033 T1036 - Masquerading T1041 T1046 T1047 T1048 T1049 T1053 T1055 T1055.001 T1056 T1057 T1059 T1059.001 T1059.003 T1059.005 T1060 T1068 - Exploitation for Privilege Escalation T1069 T1070 T1071 T1071.001 T1074 T1074.001 T1074.002 T1078 T1078.002 T1078.003 T1081 T1082 T1083 T1085 T1087 T1090 T1090.003 T1095 T1102 - Web Service T1102.003 T1105 T1106 T1110 T1111 T1112 T1113 T1114 T1114.001 T1115 T1119 T1120 T1124 T1127 T1130 T1132 T1133 T1134 T1135 T1136 T1137 T1140 - Deobfuscate/Decode Files or Information T1170 T1176 T1185 T1189 T1190 - Exploit Public-Facing Application T1195 T1197 T1199 - Trusted Relationship T1203 T1204 - User Execution T1204.001 T1204.002 T1210 T1212 T1213 T1213.006 T1217 T1218 - Signed Binary Proxy Execution T1218.010 T1482 T1485 T1486 T1489 T1490 - Inhibit System Recovery T1497 T1497.003 T1498 - Network Denial of Service T1503 T1505 T1505.003 T1518 T1528 T1529 T1530 T1531 T1534 T1539 T1543 T1546 T1546.003 T1547 T1547.001 T1547.009 T1548 T1550 T1552 T1552.001 T1553 - Subvert Trust Controls T1553.002 T1555 T1558 T1558.003 T1559 T1559.002 T1560 T1561 T1562 T1562.001 T1562.004 T1564 T1566 - Phishing T1566.001 T1566.002 T1567 T1567.002 T1571 T1572 - Protocol Tunneling T1573 T1574 T1583 T1583.001 T1584 T1584.004 T1584.008 T1585 T1585.001 T1585.002 T1586 T1586.001 T1586.002 T1587 T1587.004 T1588 T1588.006 T1589 T1589.001 T1590 - Gather Victim Network Information T1594 T1595 - Active Scanning T1595.002 T1615 T1686