APT5

G1023

Threat group.View on attack.mitre.org

About this group

APT5 is a China-based espionage actor that has been active since at least 2007 primarily targeting the telecommunications, aerospace, and defense industries throughout the U.S., Europe, and Asia. APT5 has displayed advanced tradecraft and significant interest in compromising networking devices and their underlying software including through the use of zero-day exploits.

Techniques used29

Procedure examples29

TechniqueProcedure example
T1003.001
LSASS Memory

APT5 has used the Task Manager process to target LSASS process memory in order to obtain NTLM password hashes. APT5 has also dumped clear text passwords and hashes from memory using Mimikatz hosted through an RDP mapped drive.

T1003.002
Security Account Manager

APT5 has copied and exfiltrated the SAM Registry hive from targeted systems.

T1021.001
Remote Desktop Protocol

APT5 has moved laterally throughout victim environments using RDP.

T1021.004
SSH

APT5 has used SSH for lateral movement in compromised environments including for enabling access to ESXi host servers.

T1036.005
Match Legitimate Resource Name or Location

APT5 has named exfiltration archives to mimic Windows Updates at times using filenames with a `KB<digits>.zip` pattern.

T1049
System Network Connections Discovery

APT5 has used the BLOODMINE utility to collect data on web requests from Pulse Secure Connect logs.

T1053.003
Cron

APT5 has made modifications to the crontab file including in `/var/cron/tabs/`.

T1055
Process Injection

APT5 has used the CLEANPULSE utility to insert command line strings into a targeted process to alter its functionality.

T1056.001
Keylogging

APT5 has used malware with keylogging capabilities to monitor the communications of targeted entities.

T1057
Process Discovery

APT5 has used Windows-based utilities to carry out tasks including tasklist.exe.

T1059.001
PowerShell

APT5 has used PowerShell to accomplish tasks within targeted environments.

T1059.003
Windows Command Shell

APT5 has used cmd.exe for execution on compromised systems.

T1070
Indicator Removal

APT5 has used the THINBLOOD utility to clear SSL VPN log files located at `/home/runtime/logs`.

T1070.003
Clear Command History

APT5 has cleared the command history on targeted ESXi servers.

T1070.004
File Deletion

APT5 has deleted scripts and web shells to evade detection.

View all 29 procedure examples

Software13

Campaigns1

References6

  1. FireEye Southeast Asia Threat Landscape March 2015 Open source
    FireEye. (2015, March). SOUTHEAST ASIA: AN EVOLVING CYBER THREAT LANDSCAPE. Retrieved February 5, 2024.
  2. Mandiant Advanced Persistent Threats Open source
    Mandiant. (n.d.). Advanced Persistent Threats (APTs). Retrieved February 14, 2024.
  3. Mandiant Pulse Secure Update May 2021 Open source
    Perez, D. et al. (2021, May 27). Re-Checking Your Pulse: Updates on Chinese APT Actors Compromising Pulse Secure VPN Devices. Retrieved February 5, 2024.
  4. Mandiant Pulse Secure Zero-Day April 2021 Open source
    Perez, D. et al. (2021, April 20). Check Your Pulse: Suspected APT Actors Leverage Authentication Bypass Techniques and Pulse Secure Zero-Day. Retrieved February 5, 2024.
  5. Microsoft East Asia Threats September 2023 Open source
    Microsoft Threat Intelligence. (2023, September). Digital threats from East Asia increase in breadth and effectiveness. Retrieved February 5, 2024.
  6. NSA APT5 Citrix Threat Hunting December 2022 Open source
    National Security Agency. (2022, December). APT5: Citrix ADC Threat Hunting Guidance. Retrieved February 5, 2024.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.