APT5
G10232 reportsAnalyst assessment — key judgments
- Signature techniques: T1588.006 (Vulnerabilities), T1059.001 (PowerShell), T1589.001 (Credentials).
- Primary targeting: RU, US, BR.
- Resurgent after a quiet period: 1 report(s) in last 30d vs 0 prior (+100%).
- Recent movement: 6 new technique(s), 17 new infrastructure indicator(s) in the last 30 days.
- Hunt coverage 55% of 11 observed techniques (5 gap(s)).
- Assessment confidence: medium (60).
Activity & trend
Movement — last 30 days
Vulnerabilities in this actor's reporting · 2
- CVE-2019-0708KEV1 rpt
- CVE-2020-0688KEV1 rpt
Overview
APT5 is a China-based espionage actor that has been active since at least 2007 primarily targeting the telecommunications, aerospace, and defense industries throughout the U.S., Europe, and Asia. APT5 has displayed advanced tradecraft and significant interest in compromising networking devices and their underlying software including through the use of zero-day exploits.(Citation: NSA APT5 Citrix Threat Hunting December 2022)(Citation: Microsoft East Asia Threats September 2023)(Citation: Mandiant Pulse Secure Zero-Day April 2021)(Citation: Mandiant Pulse Secure Update May 2021)(Citation: FireEye Southeast Asia Threat Landscape March 2015)(Citation: Mandiant Advanced Persistent Threats)
ATT&CK technique matrix
- T1588.006 · Vulnerabilitiesconf 602
- T1059.001 · PowerShellconf 602
- T1589.001 · Credentialsconf 602
- T1053.005 · Scheduled Taskconf 601
- T1204.002 · Malicious Fileconf 601
- T1590.005 · IP Addressesconf 601evidence: NightEagle targets Russian companies
- T1087.001 · Local Accountconf 601evidence: NightEagle targets Russian companies
- T1136.001 · Local Accountconf 601evidence: NightEagle targets Russian companies
- T1583.006 · Web Servicesconf 601evidence: NightEagle targets Russian companies
- T1584.006 · Web Servicesconf 601evidence: NightEagle targets Russian companies
- T1078.002 · Domain Accountsconf 601evidence: NightEagle targets Russian companies
Threat catalogue · engineering roadmap
Uncovered techniques you flagged for hunt / detection build-out, aggregated across every actor you visit. Stored locally in your browser.
Infrastructure
Relationships
Activity
| Title | Source | Severity | Collected |
|---|