APT40 is a China-based cyber espionage threat actor also tracked as TA423, Red Ladon, Leviathan, and GADOLINIUM. The group has been active since at least 2013 and is associated with intelligence collection operations aligned with Chinese strategic interests, particularly maritime and regional geopolitical priorities. APT40 has targeted government agencies, media organizations, and industrial enterprises, with a notable focus on Australian entities, Malaysian interests, and organizations connected to offshore energy and heavy industry projects in the South China Sea and the Strait of Taiwan. Observed targeting has included Australian federal and local government bodies, Australian news media, Malaysian entities, and global heavy industry manufacturers supporting offshore wind and gas projects. The actor has used phishing to gain initial access or deliver reconnaissance tooling, including campaigns that impersonated media organizations and directed victims to fraudulent news-themed websites. In one documented operation, APT40 deployed the ScanBox reconnaissance framework, a modular JavaScript platform used to profile victims and selectively support follow-on intrusion activity. Observed ScanBox functionality included browser and system fingerprinting, plugin enumeration, keylogging, peer-to-peer communication support via WebRTC/STUN, and checks for security software. The group has also been linked to earlier phishing campaigns using malicious RTF documents with template injection and DLL sideloading to deliver Meterpreter shellcode. APT40’s tradecraft reflects a mature espionage operator emphasizing reconnaissance, tailored social engineering, modular payload delivery, and defense-aware victim profiling. Its operations consistently align with intelligence collection rather than disruptive or financially motivated objectives.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
1 distinct technique observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.