NEW: Group Profiler — instant APT intel lookup. Try it →

APT5

G1023 China MITRE ATT&CK →

Also known as: Mulberry Typhoon · MANGANESE · BRONZE FLEETWOOD · Keyhole Panda · UNC2630

Overview

APT5 is a China-based espionage actor that has been active since at least 2007 primarily targeting the telecommunications, aerospace, and defense industries throughout the U.S., Europe, and Asia. APT5 has displayed advanced tradecraft and significant interest in compromising networking devices and their underlying software including through the use of zero-day exploits.

Naming & attribution

APT5 is tracked under 6 names across the industry. It uses 29 documented ATT&CK techniques — more than 64% of the 174 groups tracked here. Activity attributed since at least 2007.

Who calls this group what — MITRE lists each alias with the report that used it, but not which vendor coined it.
NameFirst reported by
Mulberry TyphoonMicrosoft
MANGANESEMicrosoft
BRONZE FLEETWOODSecureworks CTU
Keyhole PandaMicrosoft
UNC2630National Security Agency

Distinctive techniques

Techniques this group uses that are rare across the other 173 tracked groups — these carry more signal than the near-universal ones.

  • T1554 Compromise Host Software Binary — used by 2 of 174 groups
  • T1053.003 Cron — used by 3 of 174 groups
  • T1583.005 Botnet — used by 3 of 174 groups

Closest groups by technique overlap

Computed from shared ATT&CK techniques. Overlap is not attribution — distinct actors converge on the same tradecraft — but a high share is a useful pivot.

  • FIN13 — 16 shared techniques (24% overlap)
  • APT3 China — 14 shared techniques (24% overlap)
  • Agrius Iran — 10 shared techniques (24% overlap)
  • menuPass China — 14 shared techniques (23% overlap)
  • Aquatic Panda China — 12 shared techniques (23% overlap)
  • Play — 10 shared techniques (22% overlap)

Targets

Electronic · Technology · Telecommunications

Capabilities

  • Exploitation of public-facing / client applications — ATT&CK T1190
  • Custom malware/implant development — ATT&CK: 8 attributed custom malware families

TTPs — 29 techniques across 10 tactics

Resource Development

Initial Access

Execution

Defense Impairment

Credential Access

Lateral Movement

Collection

Tools & malware (13)

Tasklist · PoisonIvy · RAPIDPULSE · PcShare · Mimikatz · SLOWPULSE · SLIGHTPULSE · Skeleton Key · Net · PACEMAKER · gh0st RAT · PULSECHECK · netstat

Reporting (3)