APT5 is a China-aligned cyber espionage threat actor associated with long-running intrusions against government, defense, financial, telecommunications, and other strategic-sector targets. The group is widely tracked under numerous aliases including Mulberry Typhoon, Keyhole Panda, Manganese, Bronze Fleetwood, UNC2630, TG-2754, ATG48, Auriga, Red Horus, Red Naga, Tabcteng, Covenant, Bottle, Backdoor_DPD, and CyService. Public reporting has linked portions of its activity to Chinese state interests, and Microsoft maps the actor to the China-attributed Typhoon naming family as Mulberry Typhoon. APT5 is particularly notable for operations involving edge devices and remote access infrastructure, including Pulse Secure VPN exploitation and persistence. The group has been observed modifying legitimate software components on Pulse Secure appliances to install webshell capability and maintain access, including alteration of upgrade-related scripts and other trusted files. It has also used malware families and utilities associated with appliance compromise and persistence such as ATRIUM and SLOWPULSE, alongside cleanup tooling including THINBLOOD to remove VPN log evidence. Operationally, APT5 demonstrates mature post-compromise tradecraft. Observed behaviors include use of command interpreters and PowerShell for execution, Windows utilities for host interaction, RDP for lateral movement, process injection, timestomping, staging data prior to exfiltration, and deletion of scripts, web shells, and other artifacts to reduce forensic visibility. The group has also used utilities such as BLOODMINE for file discovery and has cleared or altered logs and other evidence on compromised systems. Reporting further associates APT5 with use of proxy or anonymization infrastructure as part of command-and-control or operational concealment. The actor’s objectives are consistent with intelligence collection and long-term access rather than disruptive or purely financially motivated operations. Victimology and tradecraft indicate a focus on stealthy persistence, credential and data theft, and exploitation of trusted administrative pathways and perimeter systems. High-confidence reporting supports characterization of APT5 as a sophisticated Chinese state-linked espionage actor with a history of targeting organizations of strategic interest and maintaining access through tailored malware, appliance-focused persistence, and disciplined anti-forensic measures.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
45 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
16 malware families attributed to this actor across reporting.
11 additional families tracked in Mallory.
12 CVEs this actor has used in observed campaigns. 12 of them exploited in the wild.
"...newly discovered critical zero-day authentication bypass vulnerability (CVE-2021-22893) that is currently being exploited in the wild and for which there is no patch available yet." ... "Ivanti ... has released temporary mitigations to address the arbitrary file execution vulnerability (CVE-2021-22893, CVSS score: 10)"
On Tuesday, December 13, a joint announcement from the United States NSA and Citrix announced a zero-day vulnerability in Citrix ADC. The vulnerability (CVE-2022-27518) is a critical unauthenticated Remote Code Execution (RCE) issue currently rated as CVSS 9.8. Patches are already available from Citrix. The NSA attributes the zero-day to APT5, a Chinese hacking collective.
This detection identifies instances where Windows Explorer.exe spawns PowerShell or cmd.exe processes, particularly focusing on executions initiated by LNK files. This behavior is associated with the ZDI-CAN-25373 Windows shortcut zero-day vulnerability, where specially crafted LNK files are used to trigger malicious code execution through cmd.exe or powershell.exe. This technique has been actively exploited by multiple APT groups in targeted attacks through both HTTP and SMB delivery methods.
"By exploiting multiple Pulse Secure VPN weaknesses (CVE-2019-11510, CVE-2020-8260, CVE-2020-8243, and CVE-2021-22893), UNC2630 is said to have harvested login credentials..." ... "...advisory, warning businesses of active exploitation of five publicly known vulnerabilities by the Russian Foreign Intelligence Service (SVR), including CVE-2019-11510..."
This analytic identifies potential exploitation attempts of ProxyShell (CVE-2021-34473, CVE-2021-34523, CVE-2021-31207) and ProxyNotShell (CVE-2022-41040, CVE-2022-41082) vulnerabilities in Microsoft Exchange Server.
7 more CVEs tied to this actor tracked in Mallory.
17 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Mentioned only as an annotated threat actor associated with the ATT&CK technique Process Injection (T1055) in a Splunk detection entry; no campaign or activity is described.
Mentioned only as an annotation/tag associated with the ATT&CK technique Process Injection (T1055); no campaign or activity by this group is described in the content.
Mentioned only in an annotation/list associated with the detection content; no actor-specific activity is described in this reference.
Mentioned only in the detection annotation metadata; no campaign activity or actor-specific behavior is described in this content.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.