ATT&CKGroupsLeviathan

Leviathan

G0065

Threat group.View on attack.mitre.org

About this group

Leviathan is a Chinese state-sponsored cyber espionage group that has been attributed to the Ministry of State Security's (MSS) Hainan State Security Department and an affiliated front company. Active since at least 2009, Leviathan has targeted the following sectors: academia, aerospace/aviation, biomedical, defense industrial base, government, healthcare, manufacturing, maritime, and transportation across the US, Canada, Australia, Europe, the Middle East, and Southeast Asia.

Techniques used50

Procedure examples50

TechniqueProcedure example
T1003
OS Credential Dumping

Leviathan has used publicly available tools to dump password hashes, including HOMEFRY.

T1003.001
LSASS Memory

Leviathan has used publicly available tools to dump password hashes, including ProcDump and WCE.

T1021.001
Remote Desktop Protocol

Leviathan has targeted RDP credentials and used it to move through the victim environment.

T1021.004
SSH

Leviathan used ssh for internal reconnaissance.

T1027.001
Binary Padding

Leviathan has inserted garbage characters into code, presumably to avoid anti-virus detection.

T1027.003
Steganography

Leviathan has used steganography to hide stolen data inside other files stored on Github.

T1027.013
Encrypted/Encoded File

Leviathan has obfuscated code using base64.

T1027.015
Compression

Leviathan has obfuscated code using gzip compression.

T1041
Exfiltration Over C2 Channel

Leviathan has exfiltrated data over its C2 channel.

T1047
Windows Management Instrumentation

Leviathan has used WMI for execution.

T1055.001
Dynamic-link Library Injection

Leviathan has utilized techniques like reflective DLL loading to write a DLL into memory and load a shell that provides backdoor access to the victim.

T1059.001
PowerShell

Leviathan has used PowerShell for execution.

T1059.005
Visual Basic

Leviathan has used VBScript.

T1074.001
Local Data Staging

Leviathan has used C:\Windows\Debug and C:\Perflogs as staging directories.

T1074.002
Remote Data Staging

Leviathan has staged data remotely prior to exfiltration.

View all 50 procedure examples

Software17

Campaigns1

References4

  1. CISA AA21-200A APT40 July 2021 Open source
    CISA. (2021, July 19). (AA21-200A) Joint Cybersecurity Advisory – Tactics, Techniques, and Procedures of Indicted APT40 Actors Associated with China’s MSS Hainan State Security Department. Retrieved August 12, 2021.
  2. CISA Leviathan 2024 Open source
    CISA et al. (2024, July 8). People’s Republic of China (PRC) Ministry of State Security APT40 Tradecraft in Action. Retrieved February 3, 2025.
  3. FireEye Periscope March 2018 Open source
    FireEye. (2018, March 16). Suspected Chinese Cyber Espionage Group (TEMP.Periscope) Targeting U.S. Engineering and Maritime Industries. Retrieved April 11, 2018.
  4. Proofpoint Leviathan Oct 2017 Open source
    Axel F, Pierre T. (2017, October 16). Leviathan: Espionage actor spearphishes maritime and defense targets. Retrieved February 15, 2018.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.