APT5
Also reported as Mulberry Typhoon, MANGANESE, BRONZE FLEETWOOD, UNC2630, TEMP.Bottle and 18 other names. Linked to China by four sources.
Reports per quarter
Techniques seen in the last two years
- T1036.005 2 reports in ATT&CK
- T1071.001 2 reports reports only
- T1003 1 report reports only
- T1005 1 report reports only
- T1016 1 report reports only
- T1021.001 1 report in ATT&CK
- T1027 1 report reports only
- T1027.009 1 report reports only
- T1041 1 report reports only
- T1048 1 report reports only
Show all 46 techniques Show fewer
- T1049 1 report in ATT&CK
- T1053 1 report reports only
- T1057 1 report in ATT&CK
- T1059 1 report reports only
- T1059.003 1 report in ATT&CK
- T1070 1 report in ATT&CK
- T1070.004 1 report in ATT&CK
- T1082 1 report reports only
- T1098 1 report reports only
- T1105 1 report reports only
- T1111 1 report reports only
- T1123 1 report reports only
- T1125 1 report reports only
- T1133 1 report reports only
- T1134.001 1 report reports only
- T1136 1 report reports only
- T1140 1 report reports only
- T1189 1 report reports only
- T1190 1 report in ATT&CK
- T1204.002 1 report reports only
- T1505.003 1 report in ATT&CK
- T1509 1 report reports only
- T1518 1 report reports only
- T1554 1 report in ATT&CK
- T1556.004 1 report reports only
- T1566.003 1 report reports only
- T1569.002 1 report reports only
- T1574 1 report reports only
- T1583.001 1 report reports only
- T1585.001 1 report reports only
- T1585.002 1 report reports only
- T1587.001 1 report reports only
- T1592.004 1 report reports only
- T1593.001 1 report reports only
- T1600 1 report reports only
- T1608.001 1 report reports only
Counts come from technique IDs in the actor's report text. “Reports only” means reports name the technique but MITRE ATT&CK® does not list it for this actor.
Also listed by ATT&CK
CVEs named in reports
- CVE-2012-0158 KEV ransomware
- CVE-2015-5119 KEV
- CVE-2017-0199 KEV ransomware
- CVE-2017-11882 KEV ransomware
- CVE-2018-0802 KEV ransomware
- CVE-2018-13379 KEV ransomware
- CVE-2018-15982 KEV ransomware
- CVE-2018-8174 KEV ransomware
- CVE-2019-10149 KEV
- CVE-2019-11510 KEV ransomware
- CVE-2019-1652 KEV
- CVE-2019-1653 KEV
Show all 35 CVEs Show fewer
- CVE-2019-19781 KEV ransomware
- CVE-2019-9670 KEV
- CVE-2020-0674 KEV
- CVE-2020-0796 KEV ransomware
- CVE-2020-10189 KEV
- CVE-2020-1380 KEV
- CVE-2020-1472 KEV ransomware
- CVE-2020-1472122
- CVE-2020-1938 KEV
- CVE-2021-20021 KEV ransomware
- CVE-2021-20023 KEV ransomware
- CVE-2021-22893 KEV ransomware
- CVE-2021-26411 KEV ransomware
- CVE-2021-26855 KEV ransomware
- CVE-2021-26857 KEV ransomware
- CVE-2021-26858 KEV ransomware
- CVE-2021-27065 KEV ransomware
- CVE-2021-31979 KEV
- CVE-2021-3197961
- CVE-2021-33771 KEV
- CVE-2021-3377162
- CVE-2021-35211 KEV ransomware
- CVE-2022-27518 KEV
KEV marks a CVE in CISA's Known Exploited Vulnerabilities Catalog, and “ransomware” marks one that the catalog records as used in ransomware campaigns.
Reports
-
PittyTiger, Pitty Panda - Threat Group Cards: A Threat Actor Encyclopedia
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor PittyTiger, Pitty Panda - Threat Group Cards: A Threat Actor Encyclopedia
-
APT 5, Keyhole Panda - Threat Group Cards: A Threat Actor Encyclopedia
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor APT 5, Keyhole Panda - Threat Group Cards: A Threat Actor Encyclopedia
Show all 48 reports Show fewer
-
Old Bot in New Bottle- Amadey Botnet Back in Action Via Phishing Sites
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Old Bot in New Bottle- Amadey Botnet Back in Action Via Phishing Sites
-
Command And Control In The Fifth Domain
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Command And Control In The Fifth Domain
-
Advanced Persistent Threats (APTs)
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Advanced Persistent Threats (APTs)
-
Microsoft Digital Defense Report OCTOBER 2021
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Microsoft Digital Defense Report OCTOBER 2021
-
Advanced Persistent Threats (APTs)
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Advanced Persistent Threats (APTs)
-
Juniper Breach Mystery Starts to Clear With New Details on Hackers and U.S. Role (APT5)
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Juniper Breach Mystery Starts to Clear With New Details on Hackers and U.S. Role (APT5)
-
Cinobi Banking Trojan Targets Cryptocurrency Exchange Users via Malvertising
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Cinobi Banking Trojan Targets Cryptocurrency Exchange Users via Malvertising
-
Cinobi Banking Trojan Targets Users of Cryptocurrency Exchanges with New Malvertising Campaign
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Cinobi Banking Trojan Targets Users of Cryptocurrency Exchanges with New Malvertising Campaign
-
Chinese threat actors hacked NYC MTA using Pulse Secure zero-day
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Chinese threat actors hacked NYC MTA using Pulse Secure zero-day
-
Re-Checking Your Pulse- Updates on Chinese APT Actors Compromising Pulse Secure VPN Devices
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Re-Checking Your Pulse- Updates on Chinese APT Actors Compromising Pulse Secure VPN Devices
-
Multi-Factor Authentication- Headache for Cyber Actors Inspires New Attack Techniques
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Multi-Factor Authentication- Headache for Cyber Actors Inspires New Attack Techniques
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Check Your Pulse_ Suspected APT Actors Leverage Authentication Bypass Techniques and Pulse Secure Zero-Day _ FireEye Inc
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Check Your Pulse- Suspected APT Actors Leverage Authentication Bypass Techniques and Pulse Secure Zero-Day
-
Exploit Kit still sharpens a sword
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Exploit Kit still sharpens a sword
-
日本を標的としたPseudoGateキャンペーンによるSpelevo Exploit Kitを用いた攻撃について
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor 日本を標的としたPseudoGateキャンペーンによるSpelevo Exploit Kitを用いた攻撃について
-
Group-IB_Hi-Tech_Crime_Trends_2020-2021_en
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Group-IB_Hi-Tech_Crime_Trends_2020-2021_en
-
FY20 Microsoft Digital Defense Report
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor FY20 Microsoft Digital Defense Report
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Operation Overtrap Targets Japanese Online Banking Users Via Bottle Exploit Kit and Brand-New Cinobi Banking Trojan
-
Microsoft Word - V4_Tech Brief_Operation Overtrap Targets Japanese Online Banking Users-ed2.docx
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Microsoft Word - V4_Tech Brief_Operation Overtrap Targets Japanese Online Banking Users-ed2.docx
-
Unpacking Payload used in Bottle EK
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Unpacking Payload used in Bottle EK
-
Advanced Persistent Threat Groups
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Advanced Persistent Threat Groups
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor PowerPoint Presentation
-
Southeast Asia: An Evolving Cyber Threat Landscape
The original link failed its last check. Original publisher Detailsfor Southeast Asia: An Evolving Cyber Threat Landscape
-
Southeast Asia: An Evolving Cyber Threat Landscape
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Southeast Asia: An Evolving Cyber Threat Landscape
-
CrowdCasts Monthly: You Have an Adversary Problem
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor CrowdCasts Monthly: You Have an Adversary Problem
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Mandiant_APT1_Report
Newest first. Details opens the report in Explore.