APT1 is a China-linked cyber espionage threat actor widely associated with Comment Crew, Comment Panda, and PLA Unit 61398. It is one of the earliest publicly documented advanced persistent threat groups conclusively tied to Chinese state interests and is broadly assessed as operating on behalf of the People’s Liberation Army. Additional aliases include BrownFox, Group 3, Byzantine Hades, Byzantine Candor, Shanghai Group, GIF89a, and TG-8223. APT1 is known for long-running intrusion campaigns focused on intelligence collection and theft of sensitive business, technical, and operational information from victim organizations. Reported targeting has included government and public-sector entities, military-related interests, industrial and critical infrastructure organizations, and private-sector companies in sectors such as energy, information technology, and telecommunications. Documented victim geography includes the United States, India, South Korea, Vietnam, and Russia. A notable operation involved compromise of pipeline-related organizations and theft of SCADA and pipeline management project data from Telvent. Tradecraft associated with APT1 includes spearphishing for initial access, extensive use of Windows command shell and batch scripting, host and network reconnaissance, automated collection of local victim files, and use of publicly available malware for privilege escalation. Observed discovery behavior includes enumeration of network configuration and running processes through native system utilities. The group has also been associated with credential dumping, persistence, lateral movement, and exfiltration of collected data during broader intrusion operations. Public reporting has highlighted Chinese-language artifacts and keyboard-layout evidence among the indicators historically used to support attribution. APT1 is best characterized as a state-linked espionage actor whose primary objective is sustained cyber-enabled intelligence collection rather than disruption or financial extortion.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
38 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
10 malware families attributed to this actor across reporting.
5 additional families tracked in Mallory.
10 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Mentioned only as an example of an older numeric naming convention for hacking groups.
Referenced as an example of a named threat actor whose operations were monitored across victim networks and later documented in a major threat report.
Known for using credential dumping in Windows environments.
Referenced as a threat actor associated with spearphishing attachment activity involving malicious file execution and potential credential capture via UDL files.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.