{
  "name": "Adversary Atlas API",
  "version": "1.0.0",
  "description": "Read-only JSON API over the Adversary Atlas threat actor dataset. Statically generated at build time; no authentication, no rate limits.",
  "generated": "2026-07-31T01:06:07.226Z",
  "datasetCurrentAsOf": "2025-09-01",
  "license": "Data compiled from public primary sources; see /methodology/ for sourcing.",
  "actor": {
    "id": "apt1",
    "slug": "apt1",
    "name": "APT1",
    "shortName": "APT1",
    "country": "China",
    "countryCode": "CN",
    "sponsorship": "state-sponsored",
    "status": "defunct",
    "activeSince": "2006",
    "activeUntil": "2014",
    "prominence": 79,
    "mitreGroupId": "G0006",
    "tagline": "PLA Unit 61398. The first threat group ever publicly attributed to a specific military unit — the report that created the modern threat intelligence industry.",
    "bio": "APT1 matters less for what it did than for what naming it changed.\n\nMandiant's February 2013 report was the first time a private company publicly attributed a hacking campaign to a specific military unit of a foreign government, with evidence. It identified People's Liberation Army Unit 61398 of the 2nd Bureau, 3rd Department of the General Staff Department, located the operation in a purpose-built twelve-storey facility on Datong Road in the Pudong district of Shanghai, documented 141 victims across 20 industries, and profiled three individual operators by handle — \"UglyGorilla,\" \"DOTA,\" and \"SuperHard.\"\n\nThe tradecraft itself was unremarkable. Operators used spearphishing with straightforward attachments, a large but pedestrian toolset, and — critically — poor operational security, frequently connecting to victim infrastructure directly from Shanghai IP ranges. The volume was industrial: hundreds of terabytes of intellectual property, stolen methodically across industries the PRC's Five-Year Plans had designated as strategic priorities.\n\nIn May 2014 the U.S. Department of Justice indicted five Unit 61398 officers by name — the first criminal charges ever brought against state actors for cyber-enabled economic espionage.\n\nThe group ceased its documented activity following exposure. Its practical successors are the MSS provincial bureaus and contractor firms — APT10, APT40, APT31 — which conduct the same mission with far better operational security and a layer of plausible deniability between the state and the keyboard.",
    "attribution": {
      "sponsor": "China",
      "service": "People's Liberation Army — General Staff Department, 3rd Department, 2nd Bureau",
      "unit": "Unit 61398",
      "unitDetail": "Military Unit Cover Designator 61398, Datong Road, Gaoqiao, Pudong New Area, Shanghai",
      "confidence": "confirmed",
      "summary": "Attributed to PLA Unit 61398 by Mandiant in February 2013 on the basis of infrastructure analysis, operator persona tracking, and geolocation of activity to a single Shanghai facility. The U.S. Department of Justice indicted five Unit 61398 officers in May 2014 — Wang Dong, Sun Kailiang, Wen Xinyu, Huang Zhenyu, and Gu Chunhui — for economic espionage against U.S. steel, solar, and nuclear power companies. These were the first criminal charges brought against state actors for cyber economic espionage.",
      "sources": [
        {
          "org": "Mandiant",
          "title": "APT1: Exposing One of China's Cyber Espionage Units",
          "url": "https://www.mandiant.com/sites/default/files/2021-09/mandiant-apt1-report.pdf",
          "date": "2013-02-18"
        },
        {
          "org": "U.S. Department of Justice",
          "title": "U.S. Charges Five Chinese Military Hackers for Cyber Espionage Against U.S. Corporations",
          "url": "https://www.justice.gov/opa/pr/us-charges-five-chinese-military-hackers-cyber-espionage-against-us-corporations-and-labor",
          "date": "2014-05-19"
        }
      ]
    },
    "motivations": [
      "ip-theft",
      "espionage"
    ],
    "targetSectors": [
      "Manufacturing",
      "Aerospace",
      "Energy",
      "Technology",
      "Telecommunications",
      "Government",
      "Chemical",
      "Transportation",
      "Financial Services",
      "Nuclear"
    ],
    "targetCountries": [
      "United States",
      "United Kingdom",
      "Canada",
      "Israel",
      "Japan",
      "France",
      "Switzerland"
    ],
    "aliases": [
      {
        "org": "mitre",
        "name": "APT1",
        "url": "https://attack.mitre.org/groups/G0006/",
        "correlation": "exact"
      },
      {
        "org": "mandiant",
        "name": "APT1",
        "correlation": "exact"
      },
      {
        "org": "crowdstrike",
        "name": "Comment Panda",
        "correlation": "exact"
      },
      {
        "org": "symantec",
        "name": "Comment Crew",
        "correlation": "exact"
      },
      {
        "org": "secureworks",
        "name": "TG-8223",
        "correlation": "exact"
      },
      {
        "org": "cisa",
        "name": "PLA Unit 61398",
        "correlation": "exact"
      },
      {
        "org": "kaspersky",
        "name": "Comment Group",
        "correlation": "exact"
      },
      {
        "org": "recordedfuture",
        "name": "Byzantine Candor",
        "correlation": "exact",
        "note": "U.S. government designator disclosed in leaked diplomatic cables"
      }
    ],
    "tools": [
      {
        "name": "WEBC2",
        "type": "backdoor",
        "custom": true,
        "description": "Family of minimal backdoors retrieving commands hidden in HTML comments on attacker-controlled web pages — the origin of the 'Comment Crew' name."
      },
      {
        "name": "GLOOXMAIL",
        "type": "backdoor",
        "custom": true,
        "description": "Backdoor communicating over the Jabber/XMPP protocol via Google Talk infrastructure."
      },
      {
        "name": "HTRAN",
        "type": "utility",
        "custom": false,
        "description": "Connection-bouncing proxy tool used to relay traffic through intermediate hops and obscure origin."
      },
      {
        "name": "Poison Ivy",
        "type": "backdoor",
        "custom": false,
        "description": "Widely available RAT used alongside custom tooling."
      },
      {
        "name": "Mimikatz / cachedump",
        "type": "lotl",
        "custom": false,
        "description": "Credential extraction from memory and cached domain logons."
      },
      {
        "name": "Custom FTP exfiltration",
        "type": "utility",
        "custom": true,
        "description": "Scripted bulk transfer of archived intellectual property to attacker-controlled servers."
      }
    ],
    "techniques": [
      {
        "tCode": "T1566.001",
        "name": "Phishing: Spearphishing Attachment",
        "tactic": "Initial Access",
        "note": "Straightforward attachments with industry-relevant filenames"
      },
      {
        "tCode": "T1078",
        "name": "Valid Accounts",
        "tactic": "Persistence",
        "note": "Average dwell time of 356 days; longest documented was 1,764 days"
      },
      {
        "tCode": "T1102.001",
        "name": "Web Service: Dead Drop Resolver",
        "tactic": "Command and Control",
        "note": "Commands embedded in HTML comments on legitimate web pages"
      },
      {
        "tCode": "T1003",
        "name": "OS Credential Dumping",
        "tactic": "Credential Access"
      },
      {
        "tCode": "T1021.001",
        "name": "Remote Services: Remote Desktop Protocol",
        "tactic": "Lateral Movement",
        "note": "RDP from Shanghai IP ranges — poor operational security that enabled attribution"
      },
      {
        "tCode": "T1560.001",
        "name": "Archive Collected Data: Archive via Utility",
        "tactic": "Collection",
        "note": "RAR archives split for transfer, staged before bulk exfiltration"
      },
      {
        "tCode": "T1048",
        "name": "Exfiltration Over Alternative Protocol",
        "tactic": "Exfiltration",
        "note": "FTP transfer of hundreds of terabytes of intellectual property"
      },
      {
        "tCode": "T1090.002",
        "name": "Proxy: External Proxy",
        "tactic": "Command and Control",
        "note": "HTRAN relays"
      },
      {
        "tCode": "T1074.001",
        "name": "Data Staged: Local Data Staging",
        "tactic": "Collection"
      }
    ],
    "cves": [
      {
        "cveId": "CVE-2012-0158",
        "firstExploited": "2012-05-01",
        "usage": "MSCOMCTL buffer overflow embedded in lure documents — the workhorse exploit of the period, used by nearly every espionage group operating between 2012 and 2016.",
        "source": {
          "org": "Mandiant",
          "title": "APT1: Exposing One of China's Cyber Espionage Units",
          "url": "https://www.mandiant.com/sites/default/files/2021-09/mandiant-apt1-report.pdf",
          "date": "2013-02-18"
        }
      }
    ],
    "relationships": [
      {
        "relatedActorId": "apt10",
        "type": "successor",
        "confidence": "moderate",
        "note": "Not a direct lineage. Represents the structural shift after the 2015 PLA reforms, from military units to MSS provincial bureaus and contractor firms."
      },
      {
        "relatedActorId": "apt41",
        "type": "successor",
        "confidence": "low",
        "note": "Same strategic mission of intellectual property theft, executed through a contractor model with far better operational security."
      }
    ],
    "reports": [
      {
        "org": "Mandiant",
        "title": "APT1: Exposing One of China's Cyber Espionage Units",
        "url": "https://www.mandiant.com/sites/default/files/2021-09/mandiant-apt1-report.pdf",
        "date": "2013-02-18"
      },
      {
        "org": "U.S. Department of Justice",
        "title": "Indictment: US v. Wang Dong et al. — five PLA Unit 61398 officers",
        "url": "https://www.justice.gov/iso/opa/resources/5122014519132358461949.pdf",
        "date": "2014-05-19"
      }
    ],
    "campaigns": [
      {
        "id": "apt1-disclosure",
        "actorId": "apt1",
        "name": "Mandiant APT1 Disclosure",
        "date": "2013-02-18",
        "significance": "landmark",
        "targetSectors": [
          "Manufacturing",
          "Aerospace",
          "Energy",
          "Technology",
          "Telecommunications"
        ],
        "targetCountries": [
          "United States",
          "United Kingdom",
          "Canada",
          "Israel"
        ],
        "cveIds": [
          "CVE-2012-0158"
        ],
        "summary": "The first public attribution of a hacking campaign to a specific foreign military unit, with evidence. Mandiant identified PLA Unit 61398, located it to a facility in Shanghai's Pudong district, documented 141 victims across 20 industries, and profiled three individual operators — creating the modern threat intelligence industry in the process.",
        "sources": [
          {
            "org": "Mandiant",
            "title": "APT1: Exposing One of China's Cyber Espionage Units",
            "url": "https://www.mandiant.com/sites/default/files/2021-09/mandiant-apt1-report.pdf",
            "date": "2013-02-18"
          }
        ]
      }
    ],
    "flag": "🇨🇳",
    "profile": "/apt/apt1/"
  }
}