APT5
Also known as: Mulberry Typhoon · MANGANESE · BRONZE FLEETWOOD · Keyhole Panda · UNC2630
Overview
APT5 is a China-based espionage actor that has been active since at least 2007 primarily targeting the telecommunications, aerospace, and defense industries throughout the U.S., Europe, and Asia. APT5 has displayed advanced tradecraft and significant interest in compromising networking devices and their underlying software including through the use of zero-day exploits.
Naming & attribution
APT5 is tracked under 6 names across the industry. It uses 29 documented ATT&CK techniques — more than 64% of the 174 groups tracked here. Activity attributed since at least 2007.
| Name | First reported by |
|---|---|
| Mulberry Typhoon | Microsoft |
| MANGANESE | Microsoft |
| BRONZE FLEETWOOD | Secureworks CTU |
| Keyhole Panda | Microsoft |
| UNC2630 | National Security Agency |
Distinctive techniques
Techniques this group uses that are rare across the other 173 tracked groups — these carry more signal than the near-universal ones.
-
T1554Compromise Host Software Binary — used by 2 of 174 groups -
T1053.003Cron — used by 3 of 174 groups -
T1583.005Botnet — used by 3 of 174 groups
Closest groups by technique overlap
Computed from shared ATT&CK techniques. Overlap is not attribution — distinct actors converge on the same tradecraft — but a high share is a useful pivot.
Targets
Electronic · Technology · Telecommunications
Capabilities
- Exploitation of public-facing / client applications — ATT&CK T1190
- Custom malware/implant development — ATT&CK: 8 attributed custom malware families
TTPs — 29 techniques across 10 tactics
Resource Development
-
T1583.005Botnet
Initial Access
Execution
-
T1053.003Cron -
T1059.001PowerShell -
T1059.003Windows Command Shell
Persistence
-
T1098.007Additional Local or Domain Groups -
T1136.001Local Account -
T1505.003Web Shell -
T1554Compromise Host Software Binary
Stealth
-
T1036.005Match Legitimate Resource Name or Location -
T1055Process Injection -
T1070Indicator Removal -
T1070.003Clear Command History -
T1070.004File Deletion -
T1070.006Timestomp -
T1078.002Domain Accounts -
T1078.004Cloud Accounts
Defense Impairment
-
T1685Disable or Modify Tools
Credential Access
-
T1003.001LSASS Memory -
T1003.002Security Account Manager
Discovery
-
T1049System Network Connections Discovery -
T1057Process Discovery -
T1083File and Directory Discovery -
T1654Log Enumeration
Lateral Movement
-
T1021.001Remote Desktop Protocol -
T1021.004SSH
Collection
-
T1056.001Keylogging -
T1074.001Local Data Staging -
T1560.001Archive via Utility
Tools & malware (13)
Tasklist · PoisonIvy · RAPIDPULSE · PcShare · Mimikatz · SLOWPULSE · SLIGHTPULSE · Skeleton Key · Net · PACEMAKER · gh0st RAT · PULSECHECK · netstat
Reporting (3)
- Digital threats from East Asia increase in breadth and effectiveness — Microsoft Threat Intelligence
- How Microsoft names threat actors — Microsoft
- APT5: Citrix ADC Threat Hunting Guidance — National Security Agency