Threat group.View on attack.mitre.org
APT5 is a China-based espionage actor that has been active since at least 2007 primarily targeting the telecommunications, aerospace, and defense industries throughout the U.S., Europe, and Asia. APT5 has displayed advanced tradecraft and significant interest in compromising networking devices and their underlying software including through the use of zero-day exploits.
| Technique | Procedure example |
|---|---|
| T1003.001 LSASS Memory |
APT5 has used the Task Manager process to target LSASS process memory in order to obtain NTLM password hashes. APT5 has also dumped clear text passwords and hashes from memory using Mimikatz hosted through an RDP mapped drive. |
| T1003.002 Security Account Manager |
APT5 has copied and exfiltrated the SAM Registry hive from targeted systems. |
| T1021.001 Remote Desktop Protocol |
APT5 has moved laterally throughout victim environments using RDP. |
| T1021.004 SSH |
APT5 has used SSH for lateral movement in compromised environments including for enabling access to ESXi host servers. |
| T1036.005 Match Legitimate Resource Name or Location |
APT5 has named exfiltration archives to mimic Windows Updates at times using filenames with a `KB<digits>.zip` pattern. |
| T1049 System Network Connections Discovery |
APT5 has used the BLOODMINE utility to collect data on web requests from Pulse Secure Connect logs. |
| T1053.003 Cron |
APT5 has made modifications to the crontab file including in `/var/cron/tabs/`. |
| T1055 Process Injection |
APT5 has used the CLEANPULSE utility to insert command line strings into a targeted process to alter its functionality. |
| T1056.001 Keylogging |
APT5 has used malware with keylogging capabilities to monitor the communications of targeted entities. |
| T1057 Process Discovery |
APT5 has used Windows-based utilities to carry out tasks including tasklist.exe. |
| T1059.001 PowerShell |
APT5 has used PowerShell to accomplish tasks within targeted environments. |
| T1059.003 Windows Command Shell |
APT5 has used cmd.exe for execution on compromised systems. |
| T1070 Indicator Removal |
APT5 has used the THINBLOOD utility to clear SSL VPN log files located at `/home/runtime/logs`. |
| T1070.003 Clear Command History |
APT5 has cleared the command history on targeted ESXi servers. |
| T1070.004 File Deletion |
APT5 has deleted scripts and web shells to evade detection. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.