← Back to list

APT40

APT40, also known as TEMP.Periscope, Leviathan, and many other aliases, is a Chinese cyber-espionage group attributed to the Chinese…

Omer AbdalGader Babiker · 2026-04-09 18:41 · 0 claps · 3.2 min read
#cyberattack #cyber-espionage #apt40 #apt-group
Open on Medium ↗

APT40

APT40, also known as TEMP.Periscope, Leviathan, and many other aliases, is a Chinese cyber-espionage group attributed to the Chinese Ministry of State Security (MSS). Active since at least 2009.

What is APT40

APT40 — aka BRONZE MOHAWK, FEVERDREAM, G0065, Gadolinium, GreenCrash, Hellsing, Kryptonite Panda, Leviathan, MUDCARP, Periscope, Temp.Periscope, and Temp.Jumper is located in Haikou, Hainan Province, People’s Republic of China (PRC), and has been active since at least 2009.

APT40 has targeted governmental organizations, companies, and universities in a wide range of industries — including biomedical, robotics, and maritime research across the United States, Canada, Europe, the Middle East, and the South China Sea area, as well as industries included in China’s Belt and Road Initiative.

APT40 has used a variety of tactics and techniques and a large library of custom and open-source malware much of which is shared with multiple other suspected Chinese groups to establish initial access via user and administrator credentials, enable lateral movement once inside the network, and locate high value assets in order to exfiltrate data.

Techniques and Tools

  • Initial Compromise: Uses spear-phishing emails, watering hole attacks, and malicious attachments to gain initial access.
  • Persistence: Implements custom malware, backdoors, and Remote Access Trojans (RATs) to maintain long-term access.
  • Lateral Movement: Utilizes credential theft, Pass-the-Hash techniques, and exploitation of network vulnerabilities.
  • Data Exfiltration: Employs encrypted channels, FTP, and legitimate cloud services for exfiltration.

Persistence Mechanisms

  • Web Shells: The group frequently uses web shells (T1505.003) for persistence, especially early in the intrusion lifecycle. These tools allow APT40 to maintain access to compromised systems even if initial exploitation vectors are closed.
  • Establishing Long-Term Access: After gaining initial access, APT40 focuses on establishing and maintaining persistence to ensure continued access to the victim’s environment. This early-stage persistence is a hallmark of their operations and can be observed in all intrusions regardless of the extent of further compromise.

Command and Control (C2) Infrastructure

  • Dynamic C2 Tactics: APT40 has previously used compromised websites as Command and Control (C2) hosts for its operations, recently they have shifted towards using compromised devices as C2 infrastructure.
  • Leased Infrastructure: While the group occasionally uses procured or leased infrastructure for victim-facing C2 operations, this method appears to be in relative decline.

Operations performed

  1. Spear-phishing maritime and defense targets Proof point researchers are tracking an espionage actor targeting organizations and high-value targets in defense and government. Active since at least 2014, this actor has long-standing interest in maritime industries, naval defense contractors, and associated research institutions in the United States and Western Europe.
  2. Targeting UK-Based Engineering Company Using Russian APT Techniques Employees of a U.K.-based engineering company were among the targeted victims of a spear-phishing campaign in early July 2018. The campaign also targeted an email address possibly belonging to a freelance journalist based in Cambodia who covers Cambodian politics, human rights, and Chinese development. We believe both attacks used the same infrastructure as a reported campaign by Chinese threat actor TEMP.Periscope (also known as Leviathan), which targeted Cambodian entities in the run-up to their July 2018 elections. Crucially, TEMP.Periscope’s interest in the U.K. Engineering company they targeted dates back to attempted intrusions in May 2017.
  3. The current campaign is a sharp escalation of detected activity since summer 2017. Like multiple other Chinese cyber espionage actors, TEMP.Periscope has recently re-emerged and has been observed conducting operations with a revised toolkit. Known targets of this group have been involved in the maritime industry, as well as engineering-focused entities, and include research institutes, academic organizations, and private firms in the United States.
  4. Targeting Cambodia Ahead of July 2018 Elections FireEye has examined a range of TEMP.Periscope activity revealing extensive interest in Cambodia’s politics, with active compromises of multiple Cambodian entities related to the country’s electoral system. This includes compromises of Cambodian government entities charged with overseeing the elections, as well as the targeting of opposition figures. This campaign occurs in the run up to the country’s July 29, 2018, general elections.
  5. The Malaysian Computer Emergency Response Team, a government-backed organization, said it had “observed an increase in the number of artifacts and victims involving a campaign against Malaysian government officials.” Jan 2020
  6. Parliamentary network breached by the PRC. 2021

Tools Used

AIRBREAK, BADFLICK, BlackCoffee, China Chopper, Cobalt Strike, DADJOKE, Dadstache, Derusbi, Gh0st RAT, GRILLMARK, HOMEFRY, LUNCHMONEY, MURKYTOP, NanHaiShu, PlugX, scanbox, SeDLL, Windows Credentials Editor, ZXShell, Living off the Land.

Resources

[embed]Tactics, Techniques, and Procedures of Indicted APT40 Actors Associated with China's MSS Hainan… 01234c0e41fc23bb5e1946f69e6c6221 018d3c34a296edd32e1b39b7276dcf7f 019b68e26df8750e2f9f580b150b7293…www.cisa.gov

[embed]Leviathan Leviathan is a Chinese state-sponsored cyber espionage group that has been attributed to the Ministry of State…attack.mitre.org

[embed]Threat Group Cards: A Threat Actor Encyclopedia Names Leviathan (CrowdStrike) Kryptonite Panda (CrowdStrike) APT 40 (Mandiant) TEMP.Periscope (FireEye) TEMP.Jumper…apt.etda.or.th


메타데이터
post_id
308c8a00b8d4
slug
apt40-308c8a00b8d4
url
https://medium.com/@omeratab3/apt40-308c8a00b8d4
canonical_url
https://medium.com/@omeratab3/apt40-308c8a00b8d4
author_url
https://medium.com/@omeratab3
status
ok
fetched_at
2026-06-22 12:55:45