APT1
Also reported as Comment Crew, Comment Group, TG-8223, Group 3, Byzantine Candor and 10 other names. Linked to China by three sources.
Reports per quarter
Techniques in ATT&CK
Listed by ATT&CK
Show all 23 techniques Show fewer
No report from the last two years names a technique ID.
CVEs named in reports
- CVE-2009-1539
- CVE-2009-4324 KEV
- CVE-2010-1885
- CVE-2010-2568 KEV
- CVE-2010-2883 KEV
- CVE-2010-3333 KEV
- CVE-2010-3654
- CVE-2011-0611 KEV
- CVE-2011-1255
- CVE-2011-3402 KEV
- CVE-2011-3544 KEV
- CVE-2012-0158 KEV ransomware
Show all 94 CVEs Show fewer
- CVE-2012-0779
- CVE-2012-1723 KEV ransomware
- CVE-2012-1856 KEV
- CVE-2012-1875
- CVE-2012-1889 KEV
- CVE-2013-0634
- CVE-2013-1493
- CVE-2013-3918 KEV
- CVE-2014-0322 KEV
- CVE-2014-4148 KEV
- CVE-2014-6324 KEV
- CVE-2015-1641 KEV
- CVE-2015-1701 KEV ransomware
- CVE-2015-2360 KEV
- CVE-2015-2424 KEV
- CVE-2015-2545 KEV
- CVE-2015-2590 KEV
- CVE-2015-3043 KEV
- CVE-2015-4852 KEV
- CVE-2015-5119 KEV
- CVE-2015-7645 KEV ransomware
- CVE-2016-4171 KEV
- CVE-2016-7193 KEV
- CVE-2017-0144 KEV ransomware
- CVE-2017-0176
- CVE-2017-0199 KEV ransomware
- CVE-2017-11882 KEV ransomware
- CVE-2017-18368 KEV
- CVE-2017-5638 KEV ransomware
- CVE-2017-6327 KEV
- CVE-2017-6328
- CVE-2017-7269 KEV
- CVE-2018-0802 KEV ransomware
- CVE-2018-11776 KEV
- CVE-2018-4939 KEV
- CVE-2018-6789 KEV ransomware
- CVE-2019-0708 KEV ransomware
- CVE-2019-0803 KEV ransomware
- CVE-2019-1040
- CVE-2019-11510 KEV ransomware
- CVE-2019-11580 KEV ransomware
- CVE-2019-16759 KEV
- CVE-2019-16920 KEV
- CVE-2019-18935 KEV ransomware
- CVE-2019-19781 KEV ransomware
- CVE-2019-3369
- CVE-2019-3396 KEV ransomware
- CVE-2020-0601 KEV
- CVE-2020-0688 KEV ransomware
- CVE-2020-10189 KEV
- CVE-2020-1040 KEV
- CVE-2020-1350 KEV
- CVE-2020-1472 KEV ransomware
- CVE-2020-15505 KEV
- CVE-2020-17530 KEV
- CVE-2020-2551 KEV
- CVE-2020-2555 KEV
- CVE-2020-3118 KEV
- CVE-2020-5902 KEV ransomware
- CVE-2020-6789
- CVE-2020-8193 KEV
- CVE-2020-8195 KEV
- CVE-2020-8196 KEV
- CVE-2020-8515 KEV
- CVE-2021-26084 KEV ransomware
- CVE-2021-26855 KEV ransomware
- CVE-2021-26857 KEV ransomware
- CVE-2021-26858 KEV ransomware
- CVE-2021-27065 KEV ransomware
- CVE-2021-31207 KEV ransomware
- CVE-2021-31805
- CVE-2021-34473 KEV ransomware
- CVE-2021-34523 KEV ransomware
- CVE-2021-35394 KEV
- CVE-2021-44228 KEV ransomware
- CVE-2022-22963 KEV
- CVE-2022-22965 KEV
- CVE-2022-26134 KEV ransomware
- CVE-2022-26138 KEV
- CVE-2022-34305
- CVE-2022-41040 KEV ransomware
- CVE-2022-41082 KEV ransomware
KEV marks a CVE in CISA's Known Exploited Vulnerabilities Catalog, and “ransomware” marks one that the catalog records as used in ransomware campaigns.
Reports
-
Hidden Lynx, Aurora Panda - Threat Group Cards: A Threat Actor Encyclopedia
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Hidden Lynx, Aurora Panda - Threat Group Cards: A Threat Actor Encyclopedia
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor PLA Unit 61486
-
Operation Shady RAT - Threat Group Cards: A Threat Actor Encyclopedia
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Operation Shady RAT - Threat Group Cards: A Threat Actor Encyclopedia
-
The original link failed its last check. Original publisher Detailsfor Council on Foreign Relations
-
GhostNet, Snooping Dragon - Threat Group Cards: A Threat Actor Encyclopedia
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor GhostNet, Snooping Dragon - Threat Group Cards: A Threat Actor Encyclopedia
Show all 138 reports Show fewer
-
Living off the Land - Threat Group Cards: A Threat Actor Encyclopedia
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Living off the Land - Threat Group Cards: A Threat Actor Encyclopedia
-
The PLA and the 8:00am-5:00pm Work Day: FireEye Confirms DOJ's Findings on APT1 Intrusion Activity
The title opens Wayback Machine, not the publisher’s page. Archived copy on ORKL Detailsfor The PLA and the 8:00am-5:00pm Work Day: FireEye Confirms DOJ's Findings on APT1 Intrusion Activity
-
Comment Crew, APT 1 - Threat Group Cards: A Threat Actor Encyclopedia
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Comment Crew, APT 1 - Threat Group Cards: A Threat Actor Encyclopedia
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Operation Shady RAT
-
ICIT Brief – China’s Espionage Dynasty: Economic Death by a Thousand Cuts
The title opens Wayback Machine, not the publisher’s page. Archived copy on ORKL Detailsfor ICIT Brief – China’s Espionage Dynasty: Economic Death by a Thousand Cuts
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Dark Pink APT unleashes malware for deeper and more sinister intrusions in the Asia-Pacific and Europe _ Group-IB Blog
-
The link to Mirror on Box failed its last check. Mirror on Box Detailsfor Modern Asia APT groups TTPs
-
Conceptualizing a Continuum of Cyber Threat Attribution
The original link failed its last check. Original publisher Detailsfor Conceptualizing a Continuum of Cyber Threat Attribution
-
Advanced Persistent Threats (APTs)
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Advanced Persistent Threats (APTs)
-
Advanced Persistent Threats (APTs)
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Advanced Persistent Threats (APTs)
-
The Art of Cyberwarfare Chinese APTs attack Russia
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor The Art of Cyberwarfare Chinese APTs attack Russia
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor The Art of Cyberwarfare
-
Elizabethan England has nothing on modern-day Russia
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Elizabethan England has nothing on modern-day Russia
-
Operation TunnelSnake _ Securelist
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Operation TunnelSnake _ Securelist
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Operation TunnelSnake
-
APT Encounters of the Third Kind
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor APT Encounters of the Third Kind
-
CSET - Academics, AI, and APTs
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor CSET - Academics, AI, and APTs
-
A Cyber Threat Intelligence Self-Study Plan- Part 1
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor A Cyber Threat Intelligence Self-Study Plan- Part 1
-
Auf Tätersuche- Herausforderungen bei der Analyse von Cyber-Angriffen
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Auf Tätersuche- Herausforderungen bei der Analyse von Cyber-Angriffen
-
从Solarwinds供应链攻击(金链熊)看APT行动中的隐蔽作战
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor 从Solarwinds供应链攻击(金链熊)看APT行动中的隐蔽作战
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor [RE018-1] Analyzing new malware of China Panda hacker group used to attack supply chain against Vietnam Government Certification Authority - Part 1
-
FIN11- Widespread Email Campaigns as Precursor for Ransomware and Data Theft
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor FIN11- Widespread Email Campaigns as Precursor for Ransomware and Data Theft
-
Alert (AA20-275A)- Potential for China Cyber Response to Heightened U.S.-China Tensions
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Alert (AA20-275A)- Potential for China Cyber Response to Heightened U.S.-China Tensions
-
Mustang Panda Recent Activity- Dll-Sideloading trojans with temporal C2 servers
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Mustang Panda Recent Activity- Dll-Sideloading trojans with temporal C2 servers
-
Reviving MuddyC3 Used by MuddyWater (IRAN) APT
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Reviving MuddyC3 Used by MuddyWater (IRAN) APT
-
The Fractured Block Campaign- CARROTBAT Used to Deliver Malware Targeting Southeast Asia
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor The Fractured Block Campaign- CARROTBAT Used to Deliver Malware Targeting Southeast Asia
-
cds19-executive-s08-achievement-unlocked.pdf
The original link failed its last check. Original publisher Detailsfor cds19-executive-s08-achievement-unlocked.pdf
-
Operation Soft Cell: A Worldwide Campaign Against Telecommunications Providers
The link to Mirror on Box failed its last check. Mirror on Box Detailsfor Operation Soft Cell: A Worldwide Campaign Against Telecommunications Providers
-
APT41: A Dual Espionage and Cyber Crime Operation
The link to Mirror on Box failed its last check. Mirror on Box Detailsfor APT41: A Dual Espionage and Cyber Crime Operation
-
The original link failed its last check. Original publisher Detailsfor Analytics
-
Operation-Taskmasters-2019-eng
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Operation-Taskmasters-2019-eng
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor report_APT41
-
OPERATION SOFT CELL- A WORLDWIDE CAMPAIGN AGAINST TELECOMMUNICATIONS PROVIDERS
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor OPERATION SOFT CELL- A WORLDWIDE CAMPAIGN AGAINST TELECOMMUNICATIONS PROVIDERS
-
Operation Soft Cell_ A Worldwide Campaign Against Telecommunications Providers
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Operation Soft Cell_ A Worldwide Campaign Against Telecommunications Providers
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor 10 Years Since Ghostnet
-
The Advanced Persistent Threat files- Lazarus Group
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor The Advanced Persistent Threat files- Lazarus Group
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor ‘Operation Oceansalt’ Attacks South Korea, U.S., and Canada With Source Code From Chinese Hacker Group
-
‘Operation Oceansalt’ Delivers Wave After Wave
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor ‘Operation Oceansalt’ Delivers Wave After Wave
-
The original link failed its last check. Original publisher Detailsfor BfV Cyber-Brief Nr. 02/2018
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor The destruction of APT3
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor The destruction of APT3
-
Iran’s Cyber Ecosystem- Who Are the Threat Actors-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Iran’s Cyber Ecosystem- Who Are the Threat Actors-
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Iran_Cyber_Final_Full_v2
-
Advanced Persistent Threat Groups
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Advanced Persistent Threat Groups
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Aurora_Operation_CCleaner
-
Writing PCRE's for applied passive network defense [Emotet]
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Writing PCRE's for applied passive network defense [Emotet]
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Operation Cloud Hopper
-
cloud-hopper-report-final-upda_72977
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor cloud-hopper-report-final-upda_72977
-
The link to Mirror on Box failed its last check. Mirror on Box Detailsfor Operation Cloud Hopper
-
Apt Reports And Opsec Evolution, Or: These Are Not The Apt Reports You Are Looking For
The link to Mirror on Box failed its last check. Mirror on Box Detailsfor Apt Reports And Opsec Evolution, Or: These Are Not The Apt Reports You Are Looking For
-
CS_organisation_CHINA_092016 (1)
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor CS_organisation_CHINA_092016 (1)
-
Bartholomew-GuerreroSaade-VB2016.indd
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Bartholomew-GuerreroSaade-VB2016.indd
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor ProjectSauron_ top level cyber-espionage platform covertly extracts encrypted government comms - Securelist
-
ICIT-Brief-China-Espionage-Dynasty
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor ICIT-Brief-China-Espionage-Dynasty
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Please Read
-
Red Line Drawn: China Recalculates Its Use Of Cyber Espionage
The link to Mirror on Box failed its last check. Mirror on Box Detailsfor Red Line Drawn: China Recalculates Its Use Of Cyber Espionage
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor rpt-china-espionage
-
The original link failed its last check. Original publisher Detailsfor ib-entertainment.pdf
-
Ever Present Persistence - Established Footholds Seen in the Wild
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Ever Present Persistence - Established Footholds Seen in the Wild
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor PowerPoint Presentation
-
The link to Mirror on Box failed its last check. Mirror on Box Detailsfor Operation Beebus
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Operation Duststorm
-
The_Mystery_of_Duqu_2_0_a_sophisticated_cyberespionage_actor_returns
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor The_Mystery_of_Duqu_2_0_a_sophisticated_cyberespionage_actor_returns
-
Vinself now with steganography - Airbus D&S CyberSecurity blog
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Vinself now with steganography - Airbus D&S CyberSecurity blog
-
ScanBox framework – who’s affected, and who’s using it? - Cyber security updates
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor ScanBox framework – who’s affected, and who’s using it? - Cyber security updates
-
WORLD WAR C : Understanding Nation-State Motives Behind Today’s Advanced Cyber Attacks
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor WORLD WAR C : Understanding Nation-State Motives Behind Today’s Advanced Cyber Attacks
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor sec14-paper-blond
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Targeted_Attacks_Lense_NGO
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Putter Panda
-
Snake Campaign & Cyber Espionage Toolkit
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Snake Campaign & Cyber Espionage Toolkit
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor A Detailed Examination of the Siesta Campaign « A Detailed Examination of the Siesta Campaign | FireEye Inc
-
A Detailed Examination of the Siesta Campaign
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor A Detailed Examination of the Siesta Campaign
-
Analysis of DHS NCCIC Indicators
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Analysis of DHS NCCIC Indicators
-
targeted_attacks_against_the_energy_sector
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor targeted_attacks_against_the_energy_sector
-
World War C: Understanding Nation-State Motives Behind Today's Advanced Cyber Attacks
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor World War C: Understanding Nation-State Motives Behind Today's Advanced Cyber Attacks
-
CrowdCasts Monthly: You Have an Adversary Problem
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor CrowdCasts Monthly: You Have an Adversary Problem
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Shady RAT
-
Hidden Lynx – Professional Hackers for Hire
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Hidden Lynx – Professional Hackers for Hire
-
Hidden Lynx – Professional Hackers for Hire
The title opens Wayback Machine, not the publisher’s page. Archived copy on ORKL Detailsfor Hidden Lynx – Professional Hackers for Hire
-
Hidden Lynx: Professional Hackers For Hire
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Hidden Lynx: Professional Hackers For Hire
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Taleret strings - APT (1)
-
Crude Faux: An Analysis Of Cyber Conflict Within The Oil & Gas Industries
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Crude Faux: An Analysis Of Cyber Conflict Within The Oil & Gas Industries
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor APT1: technical backstage
-
Comment Crew: Indicators Of Compromise
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Comment Crew: Indicators Of Compromise
-
APT1- Q&A on Attacks by the Comment Crew
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor APT1- Q&A on Attacks by the Comment Crew
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor PLA Unit 61398
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor PLA Unit 61398
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Mandiant_APT1_Report
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Syrian Electronic Army
-
Alleged Apt Intrusion Set: 1.Php Group
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Alleged Apt Intrusion Set: 1.Php Group
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor enter-the-cyberdragon
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor The Lurid Downloader
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor CyberEspionage
Newest first. Details opens the report in Explore.