LiveActive security incident?Get immediate response
MITRE ATT&CK® Group

G0006: APT1

APT1 is a Chinese threat group that has been attributed to the 2nd Bureau of the People’s Liberation Army (PLA) General Staff Department’s (GSD) 3rd Department, commonly known by its Military Unit Cover Designator (MUCD) as Unit 61398. [1]

EnterpriseG0006GroupObject v1.4Modified
Glexia's Take · Automated analysis

Security context for executives and security teams

Automation confidenceHigh

APT1 is an ATT&CK group entry for a Chinese threat group attributed in the cited reporting to PLA Unit 61398. The supplied relationships make this most useful as a defensive planning reference for credential theft, Windows administration-tool abuse, remote access malware, discovery, lateral movement, and local data collection. For leaders, the value is not in assuming current exposure to APT1, but in using the group’s mapped behaviors to test whether identity controls, endpoint visibility, and incident response processes can withstand a credential-driven intrusion.

Executive priority

Prioritize this object as a readiness and control-validation case study: can the organization detect and contain credential dumping, pass-the-hash-style authentication abuse, remote execution tooling, RDP use with valid accounts, and backdoor command-and-control patterns? The business risk is operational persistence after initial access: once credentials and remote execution paths are available, containment can become an enterprise-wide identity and endpoint response problem. Executives should ask whether privileged credential protections, Windows endpoint telemetry, lateral movement monitoring, and IR playbooks produce auditable evidence during an intrusion, not just whether named malware signatures exist.

Technical view

ATT&CK provides no group-specific detection text and no platforms on the intrusion-set itself. However, the relationship set is strongly Windows-oriented through tools such as Mimikatz, pwdump, gsecdump, Cachedump, Lslsass, PsExec, Net, ipconfig, PoisonIvy, BISCUIT, CALENDAR, GLOOXMAIL, WEBC2, and related credential-access and lateral-movement techniques including LSASS Memory, Remote Desktop Protocol, discovery commands, local data collection, and network connection/configuration discovery. SOC and IR teams should validate visibility across credential material access, LSASS-related activity, suspicious use of built-in admin utilities, remote service execution patterns, RDP logons, unusual process/file naming or placement, and outbound backdoor-like communications that may mimic legitimate web, Gmail Calendar, or Jabber/XMPP-style traffic as described in related software records.

Likely telemetry

  • Windows endpoint process creation and command-line telemetry for tools and utilities such as Net, Tasklist, ipconfig, PsExec-like execution, and credential dumpers
  • Security event logs and authentication telemetry for privileged logons, RDP sessions, lateral authentication, and possible pass-the-hash-style use of account material
  • Endpoint detection telemetry around LSASS access, memory dumping behavior, registry access for cached credentials, and execution from unusual paths or with misleading names
  • Network telemetry for outbound connections, web traffic, and protocol patterns relevant to backdoors such as WEBC2, CALENDAR, and GLOOXMAIL as described in ATT&CK relationships
  • File, registry, and service telemetry for backdoor persistence indicators, remote execution artifacts, and suspicious service or task enumeration

Detection direction

  • Do not rely only on malware names. Several related items are legitimate or publicly available tools, so detection should focus on behavior: credential dumping, LSASS access, remote execution, discovery bursts, RDP use, and unusual administrative utility chains.
  • Tune for context around legitimate administration. PsExec, Net, Tasklist, ipconfig, and RDP can be normal; higher-fidelity detections usually require baselines for admin hosts, service accounts, expected remote management paths, and change windows.
  • Validate coverage for credential-access techniques first, especially LSASS Memory and tools that obtain password hashes or cached credentials, because the relationship set repeatedly references credential dumping and alternate authentication material.
  • Correlate endpoint and identity evidence. A suspicious credential dump followed by RDP, PsExec-like execution, or remote command execution should be treated differently from isolated utility execution.
  • Review network detections for backdoors that blend into expected traffic patterns, including web-based command retrieval and traffic mimicking legitimate services, while recognizing that ATT&CK does not provide detection logic for this group entry.

Mitigation priorities

  • Start with identity hardening: reduce standing administrative privileges, protect privileged accounts, and limit where high-value credentials can log on.
  • Harden credential exposure on Windows endpoints, including controls that reduce access to LSASS and cached credential material where applicable.
  • Restrict and monitor remote administration paths such as RDP and PsExec-like execution; require strong authentication, approved admin workstations, and documented exceptions.
  • Improve endpoint logging and retention before relying on detections; many relevant behaviors require process, command-line, authentication, and memory-access visibility.
  • Segment systems and limit lateral movement paths so stolen credentials or remote execution tools do not provide broad enterprise reach.
Additional notes and limits

This take is based on the official ATT&CK APT1 group object, its aliases, cited external references, and listed relationships to software and techniques. The relationship graph is the main source of defensive value because the group object itself has no official detection text, tactics, or platforms. The mapped software includes both malware and legitimate/public tools, so local baselining is essential to separate administration from suspicious use.

ATT&CK fields supplied here do not establish current activity, targeting, victim exposure, or guaranteed detection coverage. The intrusion-set platform and tactics fields are not specified, so platform references are derived only from related software and technique records. Local environment evidence is required to determine relevance, control gaps, and alert fidelity.

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Official MITRE ATT&CK definition

APT1

APT1 is a Chinese threat group that has been attributed to the 2nd Bureau of the People’s Liberation Army (PLA) General Staff Department’s (GSD) 3rd Department, commonly known by its Military Unit Cover Designator (MUCD) as Unit 61398. [1]

View the same entry on attack.mitre.org (MITRE-hosted reference; in-page links above use the Glexia ATT&CK library.)

Glexia analysis

How security teams should use this page

Treat this object as behavior context, not an attribution claim. Validate the related groups, software, data sources, and mitigations against official ATT&CK relationships and your own telemetry before making control-coverage decisions.

ATT&CK relationship table

Techniques used

This mirrors the MITRE pattern of making group, software, campaign, and technique relationships scannable. Relationship notes come from mirrored ATT&CK relationship text when available.

23 rows
DomainIDNameRelationship / procedure
EnterpriseT1003.001LSASS MemorySub-technique

APT1 has been known to use credential dumping using Mimikatz.[1]

EnterpriseT1057Process Discovery

APT1 gathered a list of running processes on the system using tasklist /v.[1]

EnterpriseT1005Data from Local System

APT1 has collected files from a local victim.[1]

EnterpriseT1550.002Pass the HashSub-technique

The APT1 group is known to have used pass the hash.[1]

EnterpriseT1583.001DomainsSub-technique

APT1 has registered hundreds of domains for use in operations.[1]

EnterpriseT1560.001Archive via UtilitySub-technique

APT1 has used RAR to compress files before moving them outside of the victim network.[1]

EnterpriseT1119Automated Collection

APT1 used a batch script to perform a series of discovery techniques and saves it to a text file.[1]

EnterpriseT1114.002Remote Email CollectionSub-technique

APT1 uses two utilities, GETMAIL and MAPIGET, to steal email. MAPIGET steals email still on Exchange servers that has not yet been archived.[1]

EnterpriseT1566.002Spearphishing LinkSub-technique

APT1 has sent spearphishing emails containing hyperlinks to malicious files.[1]

EnterpriseT1016System Network Configuration Discovery

APT1 used the ipconfig /all command to gather network configuration information.[1]

EnterpriseT1114.001Local Email CollectionSub-technique

APT1 uses two utilities, GETMAIL and MAPIGET, to steal email. GETMAIL extracts emails from archived Outlook .pst files.[1]

EnterpriseT1588.001MalwareSub-technique

APT1 used publicly available malware for privilege escalation.[1]

EnterpriseT1049System Network Connections Discovery

APT1 used the net use command to get a listing on network connections.[1]

EnterpriseT1585.002Email AccountsSub-technique

APT1 has created email accounts for later use in social engineering, phishing, and when registering domains.[1]

EnterpriseT1584.001DomainsSub-technique

APT1 hijacked FQDNs associated with legitimate websites hosted by hop points.[1]

EnterpriseT1036.005Match Legitimate Resource Name or LocationSub-technique

The file name AcroRD32.exe, a legitimate process name for Adobe's Acrobat Reader, was used by APT1 as a name for malware.[1][2]

EnterpriseT1087.001Local AccountSub-technique

APT1 used the commands net localgroup,net user, and net group to find accounts on the system.[1]

EnterpriseT1566.001Spearphishing AttachmentSub-technique

APT1 has sent spearphishing emails containing malicious attachments.[1]

EnterpriseT1135Network Share Discovery

APT1 listed connected network shares.[1]

EnterpriseT1059.003Windows Command ShellSub-technique

APT1 has used the Windows command shell to execute commands, and batch scripting to automate execution.[1]

EnterpriseT1588.002ToolSub-technique

APT1 has used various open-source tools for privilege escalation purposes.[1]

EnterpriseT1007System Service Discovery

APT1 used the commands net start and tasklist to get a listing of the services on the system.[1]

EnterpriseT1021.001Remote Desktop ProtocolSub-technique

The APT1 group is known to have used RDP during operations.[4]

Associated objects

Groups, software, and campaigns

ToolEnterprise

S0100: ipconfig

ipconfig is a Windows utility that can be used to find information about a system's TCP/IP, DNS, DHCP, and adapter configuration. [1]

ToolEnterprise

S0029: PsExec

PsExec is a free Microsoft tool that can be used to execute a program on another computer. It is used by IT administrators and attackers.[1][2]

Windows
ToolEnterprise

S0121: Lslsass

Lslsass is a publicly-available tool that can dump active logon session password hashes from the lsass process. [1]

Windows
MalwareEnterprise

S0109: WEBC2

WEBC2 is a family of backdoor malware used by APT1 as early as July 2006. WEBC2 backdoors are designed to retrieve a webpage, with commands hidden in HTML comments or special tags, from a predetermined C2 server. [1][2]

Windows
ToolEnterprise

S0002: Mimikatz

Mimikatz is a credential dumper capable of obtaining plaintext Windows account logins and passwords, along with many other features that make it useful for testing the security of networks. [1] [2]

Windows
ToolEnterprise

S0008: gsecdump

gsecdump is a publicly-available credential dumper used to obtain password hashes and LSA secrets from Windows operating systems. [1]

Windows
Relationship explorer

All related ATT&CK context

Change history

Object version and sync metadata

The fields below describe the current mirrored snapshot. When Glexia retains multiple ATT&CK source imports, you can open the table to compare the same object across releases (hashes and MITRE timestamps). For MITRE’s own release notes and roadmap, see ATT&CK resources — Updates.

ATT&CK release
19.1
Object version
1.4
Created
Modified
Raw hash
e900813c68d38ff1...
Imported snapshots across ATT&CK releases(1)
ReleaseBundle importedObject versionModifiedStatusRaw hash
19.11.4Current bundlee900813c68d3…
Raw source

Mirrored ATT&CK source object

The raw object is retained through the mirrored ATT&CK source bundle and object hash. The raw endpoint returns the exact object from the mirrored bundle when available.

Source references

External references and citations

MITRE external references are preserved separately from Glexia analysis so citations remain traceable to their original source records.

  1. [1]
    Mandiant APT1

    Mandiant. (n.d.). APT1 Exposing One of China’s Cyber Espionage Units. Retrieved July 18, 2016.

    Open source URL
  2. [2]
    Mandiant APT1 Appendix

    Mandiant. (n.d.). Appendix C (Digital) - The Malware Arsenal. Retrieved July 18, 2016.

    Open source URL
  3. [3]
    McAfee Oceansalt Oct 2018

    Sherstobitoff, R., Malhotra, A. (2018, October 18). ‘Operation Oceansalt’ Attacks South Korea, U.S., and Canada With Source Code From Chinese Hacker Group. Retrieved November 30, 2018.

    Open source URL
  4. [4]
    FireEye PLA

    FireEye Labs. (2014, May 20). The PLA and the 8:00am-5:00pm Work Day: FireEye Confirms DOJ’s Findings on APT1 Intrusion Activity. Retrieved November 17, 2024.

    Open source URL
  5. [5]
    APT1

    (Citation: Mandiant APT1)

  6. [6]
    APT1

    (Citation: Mandiant APT1)

  7. [7]
    APT1

    (Citation: Mandiant APT1)

  8. [8]
    Comment Crew

    (Citation: Mandiant APT1)

  9. [9]
    Comment Crew

    (Citation: Mandiant APT1)

  10. [10]
    Comment Crew

    (Citation: Mandiant APT1)

  11. [11]
    Comment Group

    (Citation: Mandiant APT1)

  12. [12]
    Comment Group

    (Citation: Mandiant APT1)

  13. [13]
    Comment Group

    (Citation: Mandiant APT1)

  14. [14]
    Comment Panda

    (Citation: CrowdStrike Putter Panda)

  15. [15]
    Comment Panda

    (Citation: CrowdStrike Putter Panda)

  16. [16]
    Comment Panda

    (Citation: CrowdStrike Putter Panda)

  17. [17]
    CrowdStrike Putter Panda

    Crowdstrike Global Intelligence Team. (2014, June 9). CrowdStrike Intelligence Report: Putter Panda. Retrieved January 22, 2016.

  18. [18]
    CrowdStrike Putter Panda

    Crowdstrike Global Intelligence Team. (2014, June 9). CrowdStrike Intelligence Report: Putter Panda. Retrieved January 22, 2016.

  19. [19]
    CrowdStrike Putter Panda

    Crowdstrike Global Intelligence Team. (2014, June 9). CrowdStrike Intelligence Report: Putter Panda. Retrieved January 22, 2016.

  20. [20]
    Mandiant APT1

    Mandiant. (n.d.). APT1 Exposing One of China’s Cyber Espionage Units. Retrieved July 18, 2016.

    Open source URL
  21. [21]
    Mandiant APT1

    Mandiant. (n.d.). APT1 Exposing One of China’s Cyber Espionage Units. Retrieved July 18, 2016.

    Open source URL
  22. [22]
    mitre-attackG0006
    Open source URL
  23. [23]
    mitre-attackG0006
    Open source URL
  24. [24]
    mitre-attackG0006
    Open source URL
  25. [25]
    Mandiant APT1 Appendix

    Mandiant. (n.d.). Appendix C (Digital) - The Malware Arsenal. Retrieved July 18, 2016.

    Open source URL
  26. [26]
    McAfee Oceansalt Oct 2018

    Sherstobitoff, R., Malhotra, A. (2018, October 18). ‘Operation Oceansalt’ Attacks South Korea, U.S., and Canada With Source Code From Chinese Hacker Group. Retrieved November 30, 2018.

    Open source URL
  27. [27]
    Mandiant APT1

    Mandiant. (n.d.). APT1 Exposing One of China’s Cyber Espionage Units. Retrieved July 18, 2016.

    Open source URL
  28. [28]
    Mandiant APT1

    Mandiant. (n.d.). APT1 Exposing One of China’s Cyber Espionage Units. Retrieved July 18, 2016.

    Open source URL
  29. [29]
    Mandiant APT1

    Mandiant. (n.d.). APT1 Exposing One of China’s Cyber Espionage Units. Retrieved July 18, 2016.

    Open source URL
  30. [30]
    Mandiant APT1

    Mandiant. (n.d.). APT1 Exposing One of China’s Cyber Espionage Units. Retrieved July 18, 2016.

    Open source URL
  31. [31]
    Mandiant APT1

    Mandiant. (n.d.). APT1 Exposing One of China’s Cyber Espionage Units. Retrieved July 18, 2016.

    Open source URL
  32. [32]
    Mandiant APT1

    Mandiant. (n.d.). APT1 Exposing One of China’s Cyber Espionage Units. Retrieved July 18, 2016.

    Open source URL
  33. [33]
    Mandiant APT1

    Mandiant. (n.d.). APT1 Exposing One of China’s Cyber Espionage Units. Retrieved July 18, 2016.

    Open source URL
  34. [34]
    Mandiant APT1

    Mandiant. (n.d.). APT1 Exposing One of China’s Cyber Espionage Units. Retrieved July 18, 2016.

    Open source URL
  35. [35]
    Mandiant APT1

    Mandiant. (n.d.). APT1 Exposing One of China’s Cyber Espionage Units. Retrieved July 18, 2016.

    Open source URL
  36. [36]
    Mandiant APT1

    Mandiant. (n.d.). APT1 Exposing One of China’s Cyber Espionage Units. Retrieved July 18, 2016.

    Open source URL
  37. [37]
    Mandiant APT1

    Mandiant. (n.d.). APT1 Exposing One of China’s Cyber Espionage Units. Retrieved July 18, 2016.

    Open source URL
  38. [38]
    Mandiant APT1

    Mandiant. (n.d.). APT1 Exposing One of China’s Cyber Espionage Units. Retrieved July 18, 2016.

    Open source URL
  39. [39]
    Mandiant APT1

    Mandiant. (n.d.). APT1 Exposing One of China’s Cyber Espionage Units. Retrieved July 18, 2016.

    Open source URL
  40. [40]
    Mandiant APT1

    Mandiant. (n.d.). APT1 Exposing One of China’s Cyber Espionage Units. Retrieved July 18, 2016.

    Open source URL
  41. [41]
    Mandiant APT1

    Mandiant. (n.d.). APT1 Exposing One of China’s Cyber Espionage Units. Retrieved July 18, 2016.

    Open source URL
  42. [42]
    Mandiant APT1

    Mandiant. (n.d.). APT1 Exposing One of China’s Cyber Espionage Units. Retrieved July 18, 2016.

    Open source URL
  43. [43]
    Mandiant APT1

    Mandiant. (n.d.). APT1 Exposing One of China’s Cyber Espionage Units. Retrieved July 18, 2016.

    Open source URL
  44. [44]
    Mandiant APT1

    Mandiant. (n.d.). APT1 Exposing One of China’s Cyber Espionage Units. Retrieved July 18, 2016.

    Open source URL
  45. [45]
    Mandiant APT1

    Mandiant. (n.d.). APT1 Exposing One of China’s Cyber Espionage Units. Retrieved July 18, 2016.

    Open source URL
  46. [46]
    Mandiant APT1

    Mandiant. (n.d.). APT1 Exposing One of China’s Cyber Espionage Units. Retrieved July 18, 2016.

    Open source URL
  47. [47]
    Mandiant APT1

    Mandiant. (n.d.). APT1 Exposing One of China’s Cyber Espionage Units. Retrieved July 18, 2016.

    Open source URL
  48. [48]
    Mandiant APT1

    Mandiant. (n.d.). APT1 Exposing One of China’s Cyber Espionage Units. Retrieved July 18, 2016.

    Open source URL
  49. [49]
    Mandiant APT1

    Mandiant. (n.d.). APT1 Exposing One of China’s Cyber Espionage Units. Retrieved July 18, 2016.

    Open source URL
  50. [50]
    Mandiant APT1

    Mandiant. (n.d.). APT1 Exposing One of China’s Cyber Espionage Units. Retrieved July 18, 2016.

    Open source URL
  51. [51]
    Mandiant APT1

    Mandiant. (n.d.). APT1 Exposing One of China’s Cyber Espionage Units. Retrieved July 18, 2016.

    Open source URL
  52. [52]
    Mandiant APT1

    Mandiant. (n.d.). APT1 Exposing One of China’s Cyber Espionage Units. Retrieved July 18, 2016.

    Open source URL
  53. [53]
    Mandiant APT1

    Mandiant. (n.d.). APT1 Exposing One of China’s Cyber Espionage Units. Retrieved July 18, 2016.

    Open source URL
  54. [54]
    Mandiant APT1

    Mandiant. (n.d.). APT1 Exposing One of China’s Cyber Espionage Units. Retrieved July 18, 2016.

    Open source URL
  55. [55]
    Mandiant APT1

    Mandiant. (n.d.). APT1 Exposing One of China’s Cyber Espionage Units. Retrieved July 18, 2016.

    Open source URL
  56. [56]
    Mandiant APT1

    Mandiant. (n.d.). APT1 Exposing One of China’s Cyber Espionage Units. Retrieved July 18, 2016.

    Open source URL
  57. [57]
    Mandiant APT1

    Mandiant. (n.d.). APT1 Exposing One of China’s Cyber Espionage Units. Retrieved July 18, 2016.

    Open source URL
  58. [58]
    Mandiant APT1

    Mandiant. (n.d.). APT1 Exposing One of China’s Cyber Espionage Units. Retrieved July 18, 2016.

    Open source URL
  59. [59]
    Mandiant APT1

    Mandiant. (n.d.). APT1 Exposing One of China’s Cyber Espionage Units. Retrieved July 18, 2016.

    Open source URL
  60. [60]
    Mandiant APT1

    Mandiant. (n.d.). APT1 Exposing One of China’s Cyber Espionage Units. Retrieved July 18, 2016.

    Open source URL
  61. [61]
    Mandiant APT1

    Mandiant. (n.d.). APT1 Exposing One of China’s Cyber Espionage Units. Retrieved July 18, 2016.

    Open source URL
  62. [62]
    Mandiant APT1

    Mandiant. (n.d.). APT1 Exposing One of China’s Cyber Espionage Units. Retrieved July 18, 2016.

    Open source URL
  63. [63]
    Mandiant APT1

    Mandiant. (n.d.). APT1 Exposing One of China’s Cyber Espionage Units. Retrieved July 18, 2016.

    Open source URL
  64. [64]
    Mandiant APT1

    Mandiant. (n.d.). APT1 Exposing One of China’s Cyber Espionage Units. Retrieved July 18, 2016.

    Open source URL
  65. [65]
    Mandiant APT1

    Mandiant. (n.d.). APT1 Exposing One of China’s Cyber Espionage Units. Retrieved July 18, 2016.

    Open source URL
  66. [66]
    Mandiant APT1

    Mandiant. (n.d.). APT1 Exposing One of China’s Cyber Espionage Units. Retrieved July 18, 2016.

    Open source URL
  67. [67]
    Mandiant APT1

    Mandiant. (n.d.). APT1 Exposing One of China’s Cyber Espionage Units. Retrieved July 18, 2016.

    Open source URL
  68. [68]
    Mandiant APT1

    Mandiant. (n.d.). APT1 Exposing One of China’s Cyber Espionage Units. Retrieved July 18, 2016.

    Open source URL
  69. [69]
    Mandiant APT1

    Mandiant. (n.d.). APT1 Exposing One of China’s Cyber Espionage Units. Retrieved July 18, 2016.

    Open source URL
  70. [70]
    Mandiant APT1

    Mandiant. (n.d.). APT1 Exposing One of China’s Cyber Espionage Units. Retrieved July 18, 2016.

    Open source URL
  71. [71]
    Mandiant APT1

    Mandiant. (n.d.). APT1 Exposing One of China’s Cyber Espionage Units. Retrieved July 18, 2016.

    Open source URL
  72. [72]
    Mandiant APT1

    Mandiant. (n.d.). APT1 Exposing One of China’s Cyber Espionage Units. Retrieved July 18, 2016.

    Open source URL
  73. [73]
    Mandiant APT1

    Mandiant. (n.d.). APT1 Exposing One of China’s Cyber Espionage Units. Retrieved July 18, 2016.

    Open source URL
  74. [74]
    Mandiant APT1

    Mandiant. (n.d.). APT1 Exposing One of China’s Cyber Espionage Units. Retrieved July 18, 2016.

    Open source URL
  75. [75]
    Mandiant APT1

    Mandiant. (n.d.). APT1 Exposing One of China’s Cyber Espionage Units. Retrieved July 18, 2016.

    Open source URL
  76. [76]
    Mandiant APT1

    Mandiant. (n.d.). APT1 Exposing One of China’s Cyber Espionage Units. Retrieved July 18, 2016.

    Open source URL
  77. [77]
    Mandiant APT1

    Mandiant. (n.d.). APT1 Exposing One of China’s Cyber Espionage Units. Retrieved July 18, 2016.

    Open source URL
  78. [78]
    Mandiant APT1

    Mandiant. (n.d.). APT1 Exposing One of China’s Cyber Espionage Units. Retrieved July 18, 2016.

    Open source URL
  79. [79]
    Mandiant APT1

    Mandiant. (n.d.). APT1 Exposing One of China’s Cyber Espionage Units. Retrieved July 18, 2016.

    Open source URL
  80. [80]
    Mandiant APT1

    Mandiant. (n.d.). APT1 Exposing One of China’s Cyber Espionage Units. Retrieved July 18, 2016.

    Open source URL
  81. [81]
    Mandiant APT1

    Mandiant. (n.d.). APT1 Exposing One of China’s Cyber Espionage Units. Retrieved July 18, 2016.

    Open source URL
  82. [82]
    Mandiant APT1

    Mandiant. (n.d.). APT1 Exposing One of China’s Cyber Espionage Units. Retrieved July 18, 2016.

    Open source URL
  83. [83]
    Mandiant APT1

    Mandiant. (n.d.). APT1 Exposing One of China’s Cyber Espionage Units. Retrieved July 18, 2016.

    Open source URL
  84. [84]
    Mandiant APT1

    Mandiant. (n.d.). APT1 Exposing One of China’s Cyber Espionage Units. Retrieved July 18, 2016.

    Open source URL
  85. [85]
    Mandiant APT1

    Mandiant. (n.d.). APT1 Exposing One of China’s Cyber Espionage Units. Retrieved July 18, 2016.

    Open source URL
  86. [86]
    Mandiant APT1

    Mandiant. (n.d.). APT1 Exposing One of China’s Cyber Espionage Units. Retrieved July 18, 2016.

    Open source URL
  87. [87]
    Mandiant APT1 Appendix

    Mandiant. (n.d.). Appendix C (Digital) - The Malware Arsenal. Retrieved July 18, 2016.

    Open source URL
  88. [88]
    Mandiant APT1 Appendix

    Mandiant. (n.d.). Appendix C (Digital) - The Malware Arsenal. Retrieved July 18, 2016.

    Open source URL
  89. [89]
    Mandiant APT1 Appendix

    Mandiant. (n.d.). Appendix C (Digital) - The Malware Arsenal. Retrieved July 18, 2016.

    Open source URL
  90. [90]
    Mandiant APT1 Appendix

    Mandiant. (n.d.). Appendix C (Digital) - The Malware Arsenal. Retrieved July 18, 2016.

    Open source URL
  91. [91]
    Mandiant APT1

    Mandiant. (n.d.). APT1 Exposing One of China’s Cyber Espionage Units. Retrieved July 18, 2016.

    Open source URL
  92. [92]
    Mandiant APT1

    Mandiant. (n.d.). APT1 Exposing One of China’s Cyber Espionage Units. Retrieved July 18, 2016.

    Open source URL
  93. [93]
    Mandiant APT1

    Mandiant. (n.d.). APT1 Exposing One of China’s Cyber Espionage Units. Retrieved July 18, 2016.

    Open source URL
  94. [94]
    Mandiant APT1

    Mandiant. (n.d.). APT1 Exposing One of China’s Cyber Espionage Units. Retrieved July 18, 2016.

    Open source URL
  95. [95]
    Mandiant APT1

    Mandiant. (n.d.). APT1 Exposing One of China’s Cyber Espionage Units. Retrieved July 18, 2016.

    Open source URL
  96. [96]
    Mandiant APT1

    Mandiant. (n.d.). APT1 Exposing One of China’s Cyber Espionage Units. Retrieved July 18, 2016.

    Open source URL
  97. [97]
    Mandiant APT1

    Mandiant. (n.d.). APT1 Exposing One of China’s Cyber Espionage Units. Retrieved July 18, 2016.

    Open source URL
  98. [98]
    Mandiant APT1

    Mandiant. (n.d.). APT1 Exposing One of China’s Cyber Espionage Units. Retrieved July 18, 2016.

    Open source URL
Source and licensing

Source: MITRE ATT&CK®. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation. Glexia is not affiliated with or endorsed by MITRE.