LiveActive security incident?Get immediate response
MITRE ATT&CK® Campaign

C0049: Leviathan Australian Intrusions

Leviathan Australian Intrusions consisted of at least two long-term intrusions against victims in Australia by Leviathan, relying on similar tradecraft such as external service exploitation followed by extensive credential capture and re-use to enable privilege escalation and lateral movement. Leviathan Australian Intrusions were focused on exfiltrating sensitive data including valid credentials for the victim organizations.[1]

EnterpriseC0049CampaignObject v1.0Modified
Glexia's Take · Automated analysis

Security context for executives and security teams

Automation confidenceMedium

Leviathan Australian Intrusions is a campaign describing long-term intrusions against Australian victims attributed by ATT&CK to Leviathan. Its business significance is the pattern: public-facing exploitation followed by credential capture and credential re-use, enabling privilege escalation, lateral movement, data staging, and exfiltration of sensitive data including valid credentials. For leaders, this is less a single malware problem and more a test of exposure management, identity controls, logging depth, and incident response readiness.

Executive priority

Treat this campaign as a decision point for whether the organization can withstand a credential-driven intrusion after an exposed service is compromised. Priority questions: Are public-facing applications and edge services inventoried and patched quickly? Can the SOC see credential abuse across domain, local, cloud, SaaS, SSH, SMB, and MFA-related activity? Are sensitive databases and file shares monitored for unusual collection and staging? Can incident responders rapidly revoke credentials, tokens, and sessions while preserving evidence?

Technical view

ATT&CK provides no campaign-specific detection text, so defensive validation should be built from the related techniques: exploit public-facing applications, web shell persistence, system/share/domain discovery, valid account abuse, domain and local account misuse, MFA interception, token theft, unsecured credentials, Kerberoasting, SMB and SSH lateral movement, local data staging, database collection, and exfiltration over a C2 channel. Detection teams should test whether logs connect these phases into one investigation path rather than treating each alert in isolation.

Likely telemetry

  • Internet-facing application, web server, reverse proxy, and WAF logs
  • Vulnerability and external attack surface inventory for public-facing systems
  • Web server file integrity, script execution, and web shell indicators
  • Endpoint process, command-line, file creation, and archive/staging activity
  • Windows authentication, Kerberos, domain controller, SMB, and admin share events

Detection direction

  • Correlate public-facing exploitation indicators with later authentication from the same host, new web-accessible files, unusual child processes, or outbound connections.
  • Baseline and alert on abnormal use of valid accounts, especially cross-host logons, unusual SMB/admin share access, SSH access outside normal administration, and use of local accounts where domain accounts are expected.
  • Monitor for discovery behavior across systems, shares, domain trusts, and system information, while tuning out legitimate inventory, backup, and administrative tooling.
  • Validate Kerberos and service account monitoring for patterns consistent with service ticket abuse, especially where service accounts have weak hygiene or excessive privilege.
  • Review IdP, MFA, and application-token logs for suspicious session creation, token use, impossible or unusual access patterns, and access to sensitive SaaS or cloud resources.

Mitigation priorities

  • Start with exposure management: maintain an inventory of public-facing applications and prioritize remediation of exploitable weaknesses and misconfigurations.
  • Reduce credential blast radius through least privilege, privileged access controls, local account governance, service account hygiene, and prevention of password reuse.
  • Harden identity paths that enable re-use: monitor and control domain accounts, local accounts, application tokens, and MFA/session mechanisms.
  • Constrain lateral movement by limiting SMB/admin share and SSH access to required administrative paths and segmenting sensitive systems.
  • Remove insecurely stored credentials from files, configuration, shares, repositories, backups, and administrative scripts; rotate exposed credentials and tokens during response.
Additional notes and limits

The supplied ATT&CK object identifies a campaign focused on Australian victims and links it to Leviathan and a CISA advisory. The most useful defensive reading is the campaign chain: external service exploitation, credential capture/re-use, privilege escalation, lateral movement, collection, and exfiltration. Glexia should use this object to drive control validation across vulnerability management, IAM, SOC correlation, and IR credential containment.

ATT&CK does not provide official detection guidance, campaign platforms, or campaign tactics for this object. Platforms and tactics above are inferred only from related ATT&CK techniques and should be validated against the local environment. This take does not assert current exploitation, customer exposure, or guaranteed detection coverage.

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Official MITRE ATT&CK definition

Leviathan Australian Intrusions

Leviathan Australian Intrusions consisted of at least two long-term intrusions against victims in Australia by Leviathan, relying on similar tradecraft such as external service exploitation followed by extensive credential capture and re-use to enable privilege escalation and lateral movement. Leviathan Australian Intrusions were focused on exfiltrating sensitive data including valid credentials for the victim organizations.[1]

View the same entry on attack.mitre.org (MITRE-hosted reference; in-page links above use the Glexia ATT&CK library.)

Glexia analysis

How security teams should use this page

Treat this object as behavior context, not an attribution claim. Validate the related groups, software, data sources, and mitigations against official ATT&CK relationships and your own telemetry before making control-coverage decisions.

ATT&CK relationship table

Techniques used

This mirrors the MITRE pattern of making group, software, campaign, and technique relationships scannable. Relationship notes come from mirrored ATT&CK relationship text when available.

26 rows
DomainIDNameRelationship / procedure
EnterpriseT1021.002SMB/Windows Admin SharesSub-technique

Leviathan used remote shares to move laterally through victim networks during Leviathan Australian Intrusions.[1]

EnterpriseT1074.001Local Data StagingSub-technique

Leviathan stored captured credential material on local log files on victim systems during Leviathan Australian Intrusions.[1]

EnterpriseT1615Group Policy Discovery

Leviathan performed extensive Active Directory enumeration of victim environments during Leviathan Australian Intrusions.[1]

EnterpriseT1213.006DatabasesSub-technique

Leviathan gathered information from SQL servers and Building Management System (BMS) servers during Leviathan Australian Intrusions.[1]

EnterpriseT1552Unsecured Credentials

Leviathan gathered credentials hardcoded in binaries located on victim devices during Leviathan Australian Intrusions.[1]

EnterpriseT1078.002Domain AccountsSub-technique

Leviathan compromised domain credentials during Leviathan Australian Intrusions.[1]

EnterpriseT1686Disable or Modify System Firewall

Leviathan modified system firewalls to add two open listening ports on 9998 and 9999 during Leviathan Australian Intrusions.[1]

EnterpriseT1552.001Credentials In FilesSub-technique

Leviathan gathered credentials stored in files related to Building Management System (BMS) operations during Leviathan Australian Intrusions.[1]

EnterpriseT1082System Information Discovery

Leviathan performed host enumeration and data gathering operations on victim machines during Leviathan Australian Intrusions.[1]

EnterpriseT1018Remote System Discovery

Leviathan performed extensive remote host enumeration to build their own map of victim networks during Leviathan Australian Intrusions.[1]

EnterpriseT1190Exploit Public-Facing Application

Leviathan exploited public-facing web applications and appliances for initial access during Leviathan Australian Intrusions.[1]

EnterpriseT1558.003KerberoastingSub-technique

Leviathan used Kerberoasting techniques during Leviathan Australian Intrusions.[1]

EnterpriseT1041Exfiltration Over C2 Channel

Leviathan exfiltrated collected data over existing command and control channels during Leviathan Australian Intrusions.[1]

EnterpriseT1482Domain Trust Discovery

Leviathan performed Active Directory enumeration of victim environments during Leviathan Australian Intrusions.[1]

EnterpriseT1135Network Share Discovery

Leviathan scanned and enumerated remote network shares in victim environments during Leviathan Australian Intrusions.[1]

EnterpriseT1594Search Victim-Owned Websites

Leviathan enumerated compromised web application resources to identify additional endpoints and resources linkd to the website for follow-on access during Leviathan Australian Intrusions.[1]

EnterpriseT1078Valid Accounts

Leviathan used captured, valid account information to log into victim web applications and appliances during Leviathan Australian Intrusions.[1]

EnterpriseT1056Input Capture

Leviathan captured submitted multfactor authentication codes and other technical artifacts related to remote access sessions during Leviathan Australian Intrusions.[1]

EnterpriseT1505.003Web ShellSub-technique

Leviathan relied extensively on web shell use following initial access for persistence and command execution purposes in victim environments during Leviathan Australian Intrusions.[1]

EnterpriseT1078.003Local AccountsSub-technique

Leviathan used captured local account information, such as service accounts, for actions during Leviathan Australian Intrusions.[1]

EnterpriseT1068Exploitation for Privilege Escalation

Leviathan exploited software vulnerabilities in victim environments to escalate privileges during Leviathan Australian Intrusions.[1]

EnterpriseT1528Steal Application Access Token

Leviathan abused access to compromised appliances to collect JSON Web Tokens (JWTs), used for creating virtual desktop sessions, during Leviathan Australian Intrusions.[1]

EnterpriseT1111Multi-Factor Authentication Interception

Leviathan abused compromised appliance access to collect multifactor authentication token values during Leviathan Australian Intrusions.[1]

EnterpriseT1021.004SSHSub-technique

Leviathan used SSH brute force techniques to move laterally within victim environments during Leviathan Australian Intrusions.[1]

EnterpriseT1212Exploitation for Credential Access

Leviathan exploited vulnerable network appliances during Leviathan Australian Intrusions, leading to the collection and exfiltration of valid credentials.[1]

EnterpriseT1588.006VulnerabilitiesSub-technique

Leviathan weaponized publicly-known vulnerabilities for initial access and other purposes during Leviathan Australian Intrusions.[1]

Associated objects

Groups, software, and campaigns

GroupEnterprise

G0065: Leviathan

Leviathan is a Chinese state-sponsored cyber espionage group that has been attributed to the Ministry of State Security's (MSS) Hainan State Security Department and an affiliated front company.[1] Active since at least 2009, Leviathan has targeted the following sectors: academia, aerospace/aviation, biomedical, defense industrial base, government, healthcare, manufacturing, maritime, and transportation across the US, Canada, Australia, Europe, the Middle East, and Southeast Asia.[1][2][3][4]

Relationship explorer

All related ATT&CK context

Change history

Object version and sync metadata

The fields below describe the current mirrored snapshot. When Glexia retains multiple ATT&CK source imports, you can open the table to compare the same object across releases (hashes and MITRE timestamps). For MITRE’s own release notes and roadmap, see ATT&CK resources — Updates.

ATT&CK release
19.1
Object version
1.0
Created
Modified
Raw hash
f6cdf1065b69d4a4...
Imported snapshots across ATT&CK releases(1)
ReleaseBundle importedObject versionModifiedStatusRaw hash
19.11.0Current bundlef6cdf1065b69…
Raw source

Mirrored ATT&CK source object

The raw object is retained through the mirrored ATT&CK source bundle and object hash. The raw endpoint returns the exact object from the mirrored bundle when available.

Source references

External references and citations

MITRE external references are preserved separately from Glexia analysis so citations remain traceable to their original source records.

  1. [1]
    CISA Leviathan 2024

    CISA et al. (2024, July 8). People’s Republic of China (PRC) Ministry of State Security APT40 Tradecraft in Action. Retrieved February 3, 2025.

    Open source URL
  2. [2]
    CISA Leviathan 2024

    CISA et al. (2024, July 8). People’s Republic of China (PRC) Ministry of State Security APT40 Tradecraft in Action. Retrieved February 3, 2025.

    Open source URL
  3. [3]
    CISA Leviathan 2024

    CISA et al. (2024, July 8). People’s Republic of China (PRC) Ministry of State Security APT40 Tradecraft in Action. Retrieved February 3, 2025.

    Open source URL
  4. [4]
    mitre-attackC0049
    Open source URL
  5. [5]
    mitre-attackC0049
    Open source URL
  6. [6]
    mitre-attackC0049
    Open source URL
  7. [7]
    CISA Leviathan 2024

    CISA et al. (2024, July 8). People’s Republic of China (PRC) Ministry of State Security APT40 Tradecraft in Action. Retrieved February 3, 2025.

    Open source URL
  8. [8]
    CISA Leviathan 2024

    CISA et al. (2024, July 8). People’s Republic of China (PRC) Ministry of State Security APT40 Tradecraft in Action. Retrieved February 3, 2025.

    Open source URL
  9. [9]
    CISA Leviathan 2024

    CISA et al. (2024, July 8). People’s Republic of China (PRC) Ministry of State Security APT40 Tradecraft in Action. Retrieved February 3, 2025.

    Open source URL
  10. [10]
    CISA Leviathan 2024

    CISA et al. (2024, July 8). People’s Republic of China (PRC) Ministry of State Security APT40 Tradecraft in Action. Retrieved February 3, 2025.

    Open source URL
  11. [11]
    CISA Leviathan 2024

    CISA et al. (2024, July 8). People’s Republic of China (PRC) Ministry of State Security APT40 Tradecraft in Action. Retrieved February 3, 2025.

    Open source URL
  12. [12]
    CISA Leviathan 2024

    CISA et al. (2024, July 8). People’s Republic of China (PRC) Ministry of State Security APT40 Tradecraft in Action. Retrieved February 3, 2025.

    Open source URL
  13. [13]
    CISA Leviathan 2024

    CISA et al. (2024, July 8). People’s Republic of China (PRC) Ministry of State Security APT40 Tradecraft in Action. Retrieved February 3, 2025.

    Open source URL
  14. [14]
    CISA Leviathan 2024

    CISA et al. (2024, July 8). People’s Republic of China (PRC) Ministry of State Security APT40 Tradecraft in Action. Retrieved February 3, 2025.

    Open source URL
  15. [15]
    CISA Leviathan 2024

    CISA et al. (2024, July 8). People’s Republic of China (PRC) Ministry of State Security APT40 Tradecraft in Action. Retrieved February 3, 2025.

    Open source URL
  16. [16]
    CISA Leviathan 2024

    CISA et al. (2024, July 8). People’s Republic of China (PRC) Ministry of State Security APT40 Tradecraft in Action. Retrieved February 3, 2025.

    Open source URL
  17. [17]
    CISA Leviathan 2024

    CISA et al. (2024, July 8). People’s Republic of China (PRC) Ministry of State Security APT40 Tradecraft in Action. Retrieved February 3, 2025.

    Open source URL
  18. [18]
    CISA Leviathan 2024

    CISA et al. (2024, July 8). People’s Republic of China (PRC) Ministry of State Security APT40 Tradecraft in Action. Retrieved February 3, 2025.

    Open source URL
  19. [19]
    CISA Leviathan 2024

    CISA et al. (2024, July 8). People’s Republic of China (PRC) Ministry of State Security APT40 Tradecraft in Action. Retrieved February 3, 2025.

    Open source URL
  20. [20]
    CISA Leviathan 2024

    CISA et al. (2024, July 8). People’s Republic of China (PRC) Ministry of State Security APT40 Tradecraft in Action. Retrieved February 3, 2025.

    Open source URL
  21. [21]
    CISA Leviathan 2024

    CISA et al. (2024, July 8). People’s Republic of China (PRC) Ministry of State Security APT40 Tradecraft in Action. Retrieved February 3, 2025.

    Open source URL
  22. [22]
    CISA Leviathan 2024

    CISA et al. (2024, July 8). People’s Republic of China (PRC) Ministry of State Security APT40 Tradecraft in Action. Retrieved February 3, 2025.

    Open source URL
  23. [23]
    CISA Leviathan 2024

    CISA et al. (2024, July 8). People’s Republic of China (PRC) Ministry of State Security APT40 Tradecraft in Action. Retrieved February 3, 2025.

    Open source URL
  24. [24]
    CISA Leviathan 2024

    CISA et al. (2024, July 8). People’s Republic of China (PRC) Ministry of State Security APT40 Tradecraft in Action. Retrieved February 3, 2025.

    Open source URL
  25. [25]
    CISA Leviathan 2024

    CISA et al. (2024, July 8). People’s Republic of China (PRC) Ministry of State Security APT40 Tradecraft in Action. Retrieved February 3, 2025.

    Open source URL
  26. [26]
    CISA Leviathan 2024

    CISA et al. (2024, July 8). People’s Republic of China (PRC) Ministry of State Security APT40 Tradecraft in Action. Retrieved February 3, 2025.

    Open source URL
  27. [27]
    CISA Leviathan 2024

    CISA et al. (2024, July 8). People’s Republic of China (PRC) Ministry of State Security APT40 Tradecraft in Action. Retrieved February 3, 2025.

    Open source URL
  28. [28]
    CISA Leviathan 2024

    CISA et al. (2024, July 8). People’s Republic of China (PRC) Ministry of State Security APT40 Tradecraft in Action. Retrieved February 3, 2025.

    Open source URL
  29. [29]
    CISA Leviathan 2024

    CISA et al. (2024, July 8). People’s Republic of China (PRC) Ministry of State Security APT40 Tradecraft in Action. Retrieved February 3, 2025.

    Open source URL
  30. [30]
    CISA Leviathan 2024

    CISA et al. (2024, July 8). People’s Republic of China (PRC) Ministry of State Security APT40 Tradecraft in Action. Retrieved February 3, 2025.

    Open source URL
  31. [31]
    CISA Leviathan 2024

    CISA et al. (2024, July 8). People’s Republic of China (PRC) Ministry of State Security APT40 Tradecraft in Action. Retrieved February 3, 2025.

    Open source URL
  32. [32]
    CISA Leviathan 2024

    CISA et al. (2024, July 8). People’s Republic of China (PRC) Ministry of State Security APT40 Tradecraft in Action. Retrieved February 3, 2025.

    Open source URL
  33. [33]
    CISA Leviathan 2024

    CISA et al. (2024, July 8). People’s Republic of China (PRC) Ministry of State Security APT40 Tradecraft in Action. Retrieved February 3, 2025.

    Open source URL
  34. [34]
    CISA Leviathan 2024

    CISA et al. (2024, July 8). People’s Republic of China (PRC) Ministry of State Security APT40 Tradecraft in Action. Retrieved February 3, 2025.

    Open source URL
  35. [35]
    CISA Leviathan 2024

    CISA et al. (2024, July 8). People’s Republic of China (PRC) Ministry of State Security APT40 Tradecraft in Action. Retrieved February 3, 2025.

    Open source URL
  36. [36]
    CISA Leviathan 2024

    CISA et al. (2024, July 8). People’s Republic of China (PRC) Ministry of State Security APT40 Tradecraft in Action. Retrieved February 3, 2025.

    Open source URL
  37. [37]
    CISA Leviathan 2024

    CISA et al. (2024, July 8). People’s Republic of China (PRC) Ministry of State Security APT40 Tradecraft in Action. Retrieved February 3, 2025.

    Open source URL
  38. [38]
    CISA Leviathan 2024

    CISA et al. (2024, July 8). People’s Republic of China (PRC) Ministry of State Security APT40 Tradecraft in Action. Retrieved February 3, 2025.

    Open source URL
  39. [39]
    CISA Leviathan 2024

    CISA et al. (2024, July 8). People’s Republic of China (PRC) Ministry of State Security APT40 Tradecraft in Action. Retrieved February 3, 2025.

    Open source URL
  40. [40]
    CISA Leviathan 2024

    CISA et al. (2024, July 8). People’s Republic of China (PRC) Ministry of State Security APT40 Tradecraft in Action. Retrieved February 3, 2025.

    Open source URL
  41. [41]
    CISA Leviathan 2024

    CISA et al. (2024, July 8). People’s Republic of China (PRC) Ministry of State Security APT40 Tradecraft in Action. Retrieved February 3, 2025.

    Open source URL
  42. [42]
    CISA Leviathan 2024

    CISA et al. (2024, July 8). People’s Republic of China (PRC) Ministry of State Security APT40 Tradecraft in Action. Retrieved February 3, 2025.

    Open source URL
  43. [43]
    CISA Leviathan 2024

    CISA et al. (2024, July 8). People’s Republic of China (PRC) Ministry of State Security APT40 Tradecraft in Action. Retrieved February 3, 2025.

    Open source URL
  44. [44]
    CISA Leviathan 2024

    CISA et al. (2024, July 8). People’s Republic of China (PRC) Ministry of State Security APT40 Tradecraft in Action. Retrieved February 3, 2025.

    Open source URL
  45. [45]
    CISA Leviathan 2024

    CISA et al. (2024, July 8). People’s Republic of China (PRC) Ministry of State Security APT40 Tradecraft in Action. Retrieved February 3, 2025.

    Open source URL
  46. [46]
    CISA Leviathan 2024

    CISA et al. (2024, July 8). People’s Republic of China (PRC) Ministry of State Security APT40 Tradecraft in Action. Retrieved February 3, 2025.

    Open source URL
  47. [47]
    CISA Leviathan 2024

    CISA et al. (2024, July 8). People’s Republic of China (PRC) Ministry of State Security APT40 Tradecraft in Action. Retrieved February 3, 2025.

    Open source URL
  48. [48]
    CISA Leviathan 2024

    CISA et al. (2024, July 8). People’s Republic of China (PRC) Ministry of State Security APT40 Tradecraft in Action. Retrieved February 3, 2025.

    Open source URL
  49. [49]
    CISA Leviathan 2024

    CISA et al. (2024, July 8). People’s Republic of China (PRC) Ministry of State Security APT40 Tradecraft in Action. Retrieved February 3, 2025.

    Open source URL
  50. [50]
    CISA Leviathan 2024

    CISA et al. (2024, July 8). People’s Republic of China (PRC) Ministry of State Security APT40 Tradecraft in Action. Retrieved February 3, 2025.

    Open source URL
  51. [51]
    CISA Leviathan 2024

    CISA et al. (2024, July 8). People’s Republic of China (PRC) Ministry of State Security APT40 Tradecraft in Action. Retrieved February 3, 2025.

    Open source URL
  52. [52]
    CISA Leviathan 2024

    CISA et al. (2024, July 8). People’s Republic of China (PRC) Ministry of State Security APT40 Tradecraft in Action. Retrieved February 3, 2025.

    Open source URL
  53. [53]
    CISA Leviathan 2024

    CISA et al. (2024, July 8). People’s Republic of China (PRC) Ministry of State Security APT40 Tradecraft in Action. Retrieved February 3, 2025.

    Open source URL
  54. [54]
    CISA Leviathan 2024

    CISA et al. (2024, July 8). People’s Republic of China (PRC) Ministry of State Security APT40 Tradecraft in Action. Retrieved February 3, 2025.

    Open source URL
  55. [55]
    CISA Leviathan 2024

    CISA et al. (2024, July 8). People’s Republic of China (PRC) Ministry of State Security APT40 Tradecraft in Action. Retrieved February 3, 2025.

    Open source URL
Source and licensing

Source: MITRE ATT&CK®. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation. Glexia is not affiliated with or endorsed by MITRE.