APT1

G0006

Threat group.View on attack.mitre.org

About this group

APT1 is a Chinese threat group that has been attributed to the 2nd Bureau of the People’s Liberation Army (PLA) General Staff Department’s (GSD) 3rd Department, commonly known by its Military Unit Cover Designator (MUCD) as Unit 61398.

Techniques used23

Procedure examples23

TechniqueProcedure example
T1003.001
LSASS Memory

APT1 has been known to use credential dumping using Mimikatz.

T1005
Data from Local System

APT1 has collected files from a local victim.

T1007
System Service Discovery

APT1 used the commands net start and tasklist to get a listing of the services on the system.

T1016
System Network Configuration Discovery

APT1 used the ipconfig /all command to gather network configuration information.

T1021.001
Remote Desktop Protocol

The APT1 group is known to have used RDP during operations.

T1036.005
Match Legitimate Resource Name or Location

The file name AcroRD32.exe, a legitimate process name for Adobe's Acrobat Reader, was used by APT1 as a name for malware.

T1049
System Network Connections Discovery

APT1 used the net use command to get a listing on network connections.

T1057
Process Discovery

APT1 gathered a list of running processes on the system using tasklist /v.

T1059.003
Windows Command Shell

APT1 has used the Windows command shell to execute commands, and batch scripting to automate execution.

T1087.001
Local Account

APT1 used the commands net localgroup,net user, and net group to find accounts on the system.

T1114.001
Local Email Collection

APT1 uses two utilities, GETMAIL and MAPIGET, to steal email. GETMAIL extracts emails from archived Outlook .pst files.

T1114.002
Remote Email Collection

APT1 uses two utilities, GETMAIL and MAPIGET, to steal email. MAPIGET steals email still on Exchange servers that has not yet been archived.

T1119
Automated Collection

APT1 used a batch script to perform a series of discovery techniques and saves it to a text file.

T1135
Network Share Discovery

APT1 listed connected network shares.

T1550.002
Pass the Hash

The APT1 group is known to have used pass the hash.

View all 23 procedure examples

Software17

Campaigns0

None recorded.

References1

  1. Mandiant APT1 Open source
    Mandiant. (n.d.). APT1 Exposing One of China’s Cyber Espionage Units. Retrieved July 18, 2016.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.