NEW: Group Profiler — instant APT intel lookup. Try it →

APT30

G0013 China Espionage MITRE ATT&CK →

Overview

APT30 is a threat group suspected to be associated with the Chinese government. While Naikon shares some characteristics with APT30, the two groups do not appear to be exact matches.

Naming & attribution

APT30 is tracked under 1 names across the industry. It uses 2 documented ATT&CK techniques — more than 5% of the 174 groups tracked here.

Who calls this group what — MITRE lists each alias with the report that used it, but not which vendor coined it.
NameFirst reported by
APT30FireEye Labs

Targets

Government

Regions

India · Malaysia · Saudi Arabia · South Korea · Thailand · United States · Vietnam

Capabilities

  • Custom malware/implant development — ATT&CK: 5 attributed custom malware families

TTPs — 2 techniques across 2 tactics

Initial Access

Execution

Tools & malware (5)

SHIPSHAPE · BACKSPACE · FLASHFLOOD · NETEAGLE · SPACESHIP

Reporting (2)