All actors

Leviathan

Also reported as TEMP.Periscope, Gingham Typhoon, TEMP.Jumper, APT40, MUDCARP and 18 other names. Linked to China by four sources.

Reports
923
Last reported
Known CVEs
323
Techniques in ATT&CK
50
Origin
China
ID
G0065
Merge evidence
48 alias matches

Reports per quarter

  1. 2011 Q2: 1 report
  2. 2011 Q3: no reports
  3. 2011 Q4: no reports
  4. 2012 Q1: no reports
  5. 2012 Q2: no reports
  6. 2012 Q3: no reports
  7. 2012 Q4: 1 report
  8. 2013 Q1: 1 report
  9. 2013 Q2: no reports
  10. 2013 Q3: 1 report
  11. 2013 Q4: no reports
  12. 2014 Q1: no reports
  13. 2014 Q2: no reports
  14. 2014 Q3: no reports
  15. 2014 Q4: 1 report
  16. 2015 Q1: 1 report
  17. 2015 Q2: 4 reports
  18. 2015 Q3: 2 reports
  19. 2015 Q4: 2 reports
  20. 2016 Q1: 1 report
  21. 2016 Q2: 1 report
  22. 2016 Q3: 1 report
  23. 2016 Q4: no reports
  24. 2017 Q1: 1 report
  25. 2017 Q2: 5 reports
  26. 2017 Q3: no reports
  27. 2017 Q4: 6 reports
  28. 2018 Q1: 8 reports
  29. 2018 Q2: 4 reports
  30. 2018 Q3: 10 reports
  31. 2018 Q4: 7 reports
  32. 2019 Q1: 13 reports
  33. 2019 Q2: 17 reports
  34. 2019 Q3: 11 reports
  35. 2019 Q4: 16 reports
  36. 2020 Q1: 28 reports
  37. 2020 Q2: 19 reports
  38. 2020 Q3: 28 reports
  39. 2020 Q4: 42 reports
  40. 2021 Q1: 73 reports
  41. 2021 Q2: 71 reports
  42. 2021 Q3: 78 reports
  43. 2021 Q4: 56 reports
  44. 2022 Q1: 65 reports
  45. 2022 Q2: 77 reports
  46. 2022 Q3: 51 reports
  47. 2022 Q4: 22 reports
  48. 2023 Q1: 24 reports
  49. 2023 Q2: 14 reports
  50. 2023 Q3: 18 reports
  51. 2023 Q4: 16 reports
  52. 2024 Q1: 12 reports
  53. 2024 Q2: 15 reports
  54. 2024 Q3: 21 reports
  55. 2024 Q4: 11 reports
  56. 2025 Q1: 13 reports
  57. 2025 Q2: 8 reports
  58. 2025 Q3: 9 reports
  59. 2025 Q4: 6 reports
  60. 2026 Q1: 6 reports
  61. 2026 Q2: 24 reports
  62. 2026 Q3: 1 report
Dated reports, 2011 Q2 to 2026 Q3.

Techniques seen in the last two years

Show all 322 techniques Show fewer

Counts come from technique IDs in the actor's report text. “Reports only” means reports name the technique but MITRE ATT&CK® does not list it for this actor.

Also listed by ATT&CK

CVEs named in reports

Show all 323 CVEs Show fewer

KEV marks a CVE in CISA's Known Exploited Vulnerabilities Catalog, and “ransomware” marks one that the catalog records as used in ransomware campaigns.

Reports

  1. CHINACHOPPER (Malware Family)

    date ORKL added it fromORKL

  2. FlawedAmmyy (Malware Family)

    date ORKL added it fromORKL

Show all 923 reports Show fewer
  1. BlackSuit Ransomware

    publisher's date The DFIR Report fromORKLDFIR Report

  2. BumbleBee: Round Two

    publisher's date The DFIR Report fromORKLDFIR Report

  3. RedSense

    Malpedia library date fromORKL

  4. Advanced Persistent Threats (APTs)

    date in the title fromORKL

  5. RedSense

    Malpedia library date fromORKL

  6. CERT-UA

    Malpedia library date fromORKL

  7. CERT-UA

    Malpedia library date fromORKL

  8. Burrowing your way into VPNs, Proxies, and Tunnels

    date in the title fromORKL

  9. RedSense

    Malpedia library date fromORKL

  10. yir-cyber-threats-annex-download.pdf

    Malpedia library date fromORKL

  11. Quantum Ransomware

    publisher's date The DFIR Report fromORKLDFIR Report

  12. RedSense

    Malpedia library date fromORKL

  13. Unmasking China’s State Hackers

    date in the title fromORKL

  14. CERT-UA

    Malpedia library date fromORKL

  15. 2021 Year In Review

    publisher's date The DFIR Report fromORKLDFIR Report

  16. 2021trends.pdf

    Malpedia library date fromORKL

  17. RedSense

    Malpedia library date fromORKL

  18. From Zero to Domain Admin

    publisher's date The DFIR Report fromORKLDFIR Report

  19. RedSense

    Malpedia library date fromORKL

  20. Microsoft Digital Defense Report OCTOBER 2021

    file creation date fromORKL

  21. Advanced Persistent Threats (APTs)

    date in the title fromORKL

  22. report-old-dogs-new-tricks.pdf

    Malpedia library date fromORKL

  23. Government points finger at China over cyber attacks

    date in the title fromORKL

  24. Statement on China’s cyber campaigns

    date in the title fromORKL

  25. Ryuk Ransomware Now Targeting Webservers

    Malpedia library date fromORKL

  26. Cobalt Strike- Favorite Tool from APT to Crimeware

    date in the title fromORKL

  27. Mustang Panda PlugX - 45.251.240.55 Pivot

    Malpedia library date fromORKL

  28. Conti Ransomware

    publisher's date The DFIR Report fromORKLDFIR Report

  29. CTIR_casestudy_2.pdf

    file creation date fromORKL

  30. CTIR_casestudy_1.pdf

    file creation date fromORKL

  31. the-operations-of-winnti-group.pdf

    Malpedia library date fromORKL

  32. mtrends-2021

    file creation date fromORKL

  33. report-bb-2021-threat-report.pdf

    Malpedia library date fromORKL

  34. Technical Analysis of Operation Diànxùn

    Malpedia library date fromORKL

  35. Bazar Drops the Anchor

    publisher's date The DFIR Report fromORKLDFIR Report

  36. CSET - Academics, AI, and APTs

    file creation date fromORKL

  37. Bazar, No Ryuk?

    publisher's date The DFIR Report fromORKLDFIR Report

  38. nao-sec.org-Royal Road ReDive

    date in the CCS '25 data nao_sec fromORKLCCS '25 data

  39. Royal Road! Re-Dive

    date in the title fromORKL

  40. China cyber attacks- the current threat landscape

    date in the title fromORKL

  41. Ryuk in 5 Hours

    publisher's date The DFIR Report fromORKLDFIR Report

  42. Ryuk's Return

    publisher's date The DFIR Report fromORKLDFIR Report

  43. Microsoft Security—detecting empires in the cloud

    date in the title fromORKL

  44. Microsoft Security—detecting empires in the cloud - Microsoft Security

    date in the CCS '25 data Microsoft fromORKLCCS '25 data

  45. Deep-dive: The DarkHotel APT

    Malpedia library date Bushido Token fromORKLCCS '25 data

  46. Ursnif via LOLbins

    publisher's date The DFIR Report fromORKLDFIR Report

  47. Catching APT41 exploiting a zero-day vulnerability

    date in the CCS '25 data Darktrace fromCCS '25 data

  48. Is APT 27 Abusing COVID-19 To Attack People !

    date in the CCS '25 data Yoroi fromCCS '25 data

  49. cybersecurity-threatscape-2019-q4-eng

    file creation date fromORKL

  50. APT 40 in Malaysia

    date in the title fromORKL

  51. Hainan Xiandun Technology Company is APT40

    date in the title fromORKL

  52. Group-IB_Hi-Tech_Crime_Trends_2019-2020_en

    file creation date fromORKL

  53. Aarhus_miniseminar_291118.pdf

    Malpedia library date fromORKL

  54. Analytics

    Malpedia library date Positive Technologies fromORKLCCS '25 data

  55. Two Birds, One STONE PANDA

    file creation date Crowdstrike fromORKL

  56. APT41: A Dual Espionage and Cyber Crime Operation

    file creation date FireEye fromORKL

  57. report_APT41

    file creation date fromORKL

  58. APT-Attacks-eng.pdf

    file creation date fromORKL

  59. Into the Fog - The Return of ICEFOG APT

    date in the title fromORKL

  60. Into the Fog - The Return of ICEFOG APT

    Malpedia library date fromORKL

  61. APT_trends_report_Q1_2019_Securelist

    file creation date fromORKL

  62. APT 40

    date in the title fromORKL

  63. Council on Foreign Relations

    Malpedia library date Council on Foreign Relations fromORKLCCS '25 data

  64. rpt-mtrends-2019.pdf

    file creation date fromORKL

  65. mpressioncss_ta_report_2019.pdf

    Malpedia library date fromORKL

  66. Accenture Strategy Templates

    Malpedia library date fromORKL

  67. APT40- Examining a China-Nexus Espionage Actor

    date in the title fromORKL

  68. rpt-mtrends-2019

    file creation date fromORKL

  69. 2018 Master Table

    file creation date fromORKL

  70. Two Birds, One STONE PANDA

    date in the CCS '25 data IntrusionTruth fromORKLCCS '25 data

  71. Two Birds, One STONE PANDA

    date in the title fromORKL

  72. BADFLICK is not so bad!

    date in the title fromORKL

  73. Bitdefender Labs

    Malpedia library date Bitdefender fromORKLCCS '25 data

  74. Advanced Persistent Threat Groups

    date in the title fromORKL

  75. security_report_20160613.pdf

    Malpedia library date fromORKL

  76. Newcomers in the Derusbi family

    Malpedia library date fromORKL

  77. VB2015_Catching_the_silent_whisper

    Malpedia library date mpun@fortinet.com, ericleung@fortinet.com, ntan@fortinet.com fromORKL

  78. Uncovering the Seven Pointed Dagger

    Malpedia library date Arbor Networks fromORKLCCS '25 data

  79. APT17_Report.pdf

    Malpedia library date fromORKL

  80. Inside a Back Door Attack

    Malpedia library date fromORKL

Newest first. Details opens the report in Explore.