G0065: Leviathan
Leviathan is a Chinese state-sponsored cyber espionage group that has been attributed to the Ministry of State Security's (MSS) Hainan State Security Department and an affiliated front company.CitationCISA AA21-200A APT40 July 2021 Active since at least 2009, Leviathan has targeted the following sectors: academia, aerospace/aviation, biomedical, defense industrial base, government, healthcare, manufacturing, maritime, and transportation across the US, Canada, Australia, Europe, the Middle East, and Southeast Asia.CitationCISA AA21-200A APT40 July 2021CitationProofpoint Leviathan Oct 2017CitationFireEye Periscope March 2018CitationCISA Leviathan 2024
Security context for executives and security teams
Leviathan matters because ATT&CK describes it as a long-running Chinese state-sponsored espionage group associated with targeting sectors where sensitive research, defense, maritime, aviation, healthcare, government, manufacturing, transportation, and similar data can affect strategic advantage and business continuity. For executives, the key issue is not just malware names: the relationship context highlights external service exploitation, credential capture and reuse, privilege escalation, lateral movement, and sensitive data exfiltration in an attributed campaign.
Executive priority
Prioritize this as a resilience and sensitive-data protection planning case if your organization operates in the listed sectors or geographies. Leaders should ask whether externally exposed services, credential stores, remote access paths, and data repositories have measurable control evidence. This object is also useful for board and audit conversations because it connects espionage risk to concrete validation areas: vulnerability management for exposed services, identity hardening, SOC visibility, incident response readiness, and evidence that credential theft and lateral movement can be detected and contained.
Technical view
ATT&CK provides no official detection text for this group, so defenders should validate coverage from the related techniques, campaign, and software relationships. Focus on credential access via OS Credential Dumping and LSASS Memory, lateral movement over RDP and SSH, use of web shells such as China Chopper, command-line administration utilities such as Net, at, and BITSAdmin, PowerShell/post-exploitation frameworks such as PowerSploit, Empire, and Cobalt Strike, and remote access/backdoor tooling including NanHaiShu, Orz, BADFLICK, Derusbi, gh0st RAT, BLACKCOFFEE, HOMEFRY, and MURKYTOP. The campaign relationship makes credential capture and reuse especially important to validate across Windows, Linux, macOS, and ESXi where those related techniques or tools list support.
Likely telemetry
- External-facing service logs, web server logs, and file integrity evidence for possible web shell placement or access patterns
- Identity and authentication logs for successful and failed logons, unusual credential reuse, RDP sessions, SSH sessions, and privilege changes
- Endpoint process creation and command-line telemetry for Net, at, BITSAdmin, PowerShell, and post-exploitation framework activity
- Windows security and EDR telemetry around LSASS access, credential dumping behavior, suspicious handles, memory access, or dump file creation
- Network, DNS, proxy, and firewall logs for remote access tooling, anonymization infrastructure such as Tor, and unusual outbound connections
Detection direction
- Because MITRE does not provide group-specific detection guidance, map detections to the related techniques and software rather than relying on the Leviathan name alone.
- Validate that credential dumping detections cover both generic OS credential access and Windows LSASS access, and tune for legitimate administrative or security-tool activity to reduce false positives.
- Correlate remote access logons over RDP and SSH with prior credential events, new administrative access, unusual source hosts, and lateral movement sequences.
- Hunt for living-off-the-land command usage involving Net, at, BITSAdmin, and PowerShell where execution context, parent process, destination, or timing is abnormal.
- For web shell risk, confirm that internet-facing application logs, server-side file writes, and web process child process execution are collected and reviewable.
Mitigation priorities
- Start with externally exposed service governance: inventory, patch prioritization, secure configuration, and monitoring evidence for internet-facing systems.
- Harden identity paths next: least privilege, privileged account separation, MFA where applicable, credential hygiene, and controls that reduce credential reuse after compromise.
- Restrict and monitor administrative remote access such as RDP and SSH, including segmentation and logging sufficient for incident reconstruction.
- Reduce credential dumping opportunity through endpoint hardening, privileged access controls, and monitoring of LSASS and other credential stores.
- Constrain abuse of built-in tools and scripting through policy, allowlisting, script logging, and administrative workflow review where operationally feasible.
Additional notes and limits
This take is based on ATT&CK group G0065, its aliases, official description, external references, and the supplied relationships. The most decision-useful relationship is the Leviathan Australian Intrusions campaign, which explicitly notes external service exploitation followed by credential capture and reuse, privilege escalation, lateral movement, and sensitive data exfiltration. The software relationships also indicate a mix of custom malware, public tools, remote access frameworks, web shells, credential tools, and built-in administrative utilities.
The ATT&CK object does not specify platforms or tactics directly and provides no official detection section. Platforms and tactics referenced here come from supplied related techniques and software, not from a group-level platform declaration. Local exposure, sector relevance, telemetry availability, and confirmed detection coverage must be validated in the organization’s own environment.
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
Leviathan
Leviathan is a Chinese state-sponsored cyber espionage group that has been attributed to the Ministry of State Security's (MSS) Hainan State Security Department and an affiliated front company.CitationCISA AA21-200A APT40 July 2021 Active since at least 2009, Leviathan has targeted the following sectors: academia, aerospace/aviation, biomedical, defense industrial base, government, healthcare, manufacturing, maritime, and transportation across the US, Canada, Australia, Europe, the Middle East, and Southeast Asia.CitationCISA AA21-200A APT40 July 2021CitationProofpoint Leviathan Oct 2017CitationFireEye Periscope March 2018CitationCISA Leviathan 2024
How security teams should use this page
Treat this object as behavior context, not an attribution claim. Validate the related groups, software, data sources, and mitigations against official ATT&CK relationships and your own telemetry before making control-coverage decisions.
All related ATT&CK context
No relationships are available in the current normalized data for this object.
Object version and sync metadata
The fields below describe the current mirrored snapshot. When Glexia retains multiple ATT&CK source imports, you can open the table to compare the same object across releases (hashes and MITRE timestamps). For MITRE’s own release notes and roadmap, see ATT&CK resources — Updates.
Mirrored ATT&CK source object
The raw object is retained through the mirrored ATT&CK source bundle and object hash. The raw endpoint returns the exact object from the mirrored bundle when available.
Source: MITRE ATT&CK®. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation. Glexia is not affiliated with or endorsed by MITRE.
