APT40 is a China-based cyber espionage threat actor active since at least 2013 and widely tracked under aliases including TA423, Red Ladon, Leviathan, and GADOLINIUM. The group is associated with intelligence collection operations aligned with Chinese strategic interests, particularly around the South China Sea and Taiwan Strait. Reported targeting has included government entities, media organizations, energy exploration and offshore energy projects, manufacturing and heavy industry firms, and related supply-chain organizations. APT40 commonly relies on phishing for initial access, using both malicious links and weaponized document attachments. Observed campaigns have used RTF template injection to retrieve remote content when a document is opened, including lures themed around Office 365 and regional political or business interests. The actor has also been linked to delivery chains involving DLL sideloading and XOR-encoded Meterpreter shellcode. In web-based operations, APT40 has used the ScanBox reconnaissance framework to profile victims and selectively advance intrusions. Observed capabilities include reconnaissance through browser and host fingerprinting, keylogging, collection of browser and system metadata, and security-product checks. Campaigns have shown tailored social engineering, victim tracking, and infrastructure overlap across operations. Public reporting has tied the group to sustained targeting of Australian interests, Malaysian entities, and organizations connected to offshore energy and industrial activity in strategically contested maritime regions. The actor’s dominant motivation is espionage.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
14 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
77 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
China-based espionage actor conducting phishing and watering-hole style campaigns delivering the ScanBox reconnaissance framework and earlier RTF template injection chains leading to DLL sideloading and Meterpreter. The group targets Australian government, media, defense, health care, Malaysian offshore energy, and supply-chain entities tied to South China Sea and Taiwan Strait energy projects.
Conducted phishing campaigns using RTF template injection with plaintext remote template URLs, targeting Malaysia and energy exploration-related entities; lures impersonated Office 365 and prompted users to enable editing/content.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.