APT40

Actor Type Nation State
Attributed to Nation China
Directly Linked Intrusion Sets Leviathan
Associated Threat Actor Hainan Xiandun Technology Development Company , Hainan State Security Department , Chinese Ministry of State Security

APT40 is a threat actor originally identified by researchers at Mandiant an attributed to the Chinese government. A 2021 US Department of Justice indictment linked the group to the Hainan State Security Department (HSSD), a provincial arm of China’s Ministry of State Security (MSS).

According to researchers at Mandiant, the group has been observed targeting organizations globally, with a focus on countries that are strategically important to the Belt and Road Initiative.

APT40 have a complex arsenal of public and private tools, some of which are shared with other China attributed threat actors. APT40 typically gain access via spear-phishing including masquerading as prominent individuals and leveraging previously compromised accounts for this purpose.

Cyber Threat Graph Context

Explore how this Intrusion Set relates to the wider threat graph

APT40 Threat Reports

Report

APT40 Advisory - PRC MSS tradecraft in action

This advisory, authored by the Australian Cyber Security Centre and multiple other international cybersecurity agencies, outlines the threat posed ...

References

MITRE ATT&CK Techniques

MITRE ATT&CK techniques observed in use by this intrusion set.