Skip to content
ChinaState-SponsoredDefunctMITRE G0006

APT1

PLA Unit 61398. The first threat group ever publicly attributed to a specific military unit — the report that created the modern threat intelligence industry.

ATTRIBUTED TOChina › People's Liberation Army — General Staff Department, 3rd Department, 2nd Bureau › Unit 61398

Open MITRE Navigator layer ↗Download profile JSON
Active
2006–2014
Motivation
IP Theft, Espionage
Aliases
8
Exploited CVEs
1
ATT&CK techniques
9
Cited sources
5

Overview

APT1 matters less for what it did than for what naming it changed.

Mandiant's February 2013 report was the first time a private company publicly attributed a hacking campaign to a specific military unit of a foreign government, with evidence. It identified People's Liberation Army Unit 61398 of the 2nd Bureau, 3rd Department of the General Staff Department, located the operation in a purpose-built twelve-storey facility on Datong Road in the Pudong district of Shanghai, documented 141 victims across 20 industries, and profiled three individual operators by handle — "UglyGorilla," "DOTA," and "SuperHard."

The tradecraft itself was unremarkable. Operators used spearphishing with straightforward attachments, a large but pedestrian toolset, and — critically — poor operational security, frequently connecting to victim infrastructure directly from Shanghai IP ranges. The volume was industrial: hundreds of terabytes of intellectual property, stolen methodically across industries the PRC's Five-Year Plans had designated as strategic priorities.

In May 2014 the U.S. Department of Justice indicted five Unit 61398 officers by name — the first criminal charges ever brought against state actors for cyber-enabled economic espionage.

The group ceased its documented activity following exposure. Its practical successors are the MSS provincial bureaus and contractor firms — APT10, APT40, APT31 — which conduct the same mission with far better operational security and a layer of plausible deniability between the state and the keyboard.

Attribution

Down to the named unit where public evidence supports it.

ChinaPeople's Liberation Army — General Staff Department, 3rd Department, 2nd BureauUnit 61398Confirmed

Military Unit Cover Designator 61398, Datong Road, Gaoqiao, Pudong New Area, Shanghai

Attributed to PLA Unit 61398 by Mandiant in February 2013 on the basis of infrastructure analysis, operator persona tracking, and geolocation of activity to a single Shanghai facility. The U.S. Department of Justice indicted five Unit 61398 officers in May 2014 — Wang Dong, Sun Kailiang, Wen Xinyu, Huang Zhenyu, and Gu Chunhui — for economic espionage against U.S. steel, solar, and nuclear power companies. These were the first criminal charges brought against state actors for cyber economic espionage.

Attributing sources

Cross-vendor naming crosswalk

8 designators across 8 organisations.

MITRE ATT&CK

index ↗
  • APT1

Assigns a stable Gxxxx group ID and adopts the most widely used public name. Deliberately conservative — MITRE merges clusters only when public reporting supports it.

CrowdStrike

index ↗
  • Comment Panda

Animal denotes attributed nation-state or motive; the adjective distinguishes clusters. The original public adversary taxonomy, in use since 2012.

Mandiant / Google Threat Intelligence

index ↗
  • APT1

APTxx for state-nexus espionage, FINxx for financially motivated, UNCxxxx ('uncategorized') for clusters not yet graduated to a named group. Many UNC numbers are later merged into an APT/FIN designator.

Secureworks CTU

index ↗
  • TG-8223

Metal prefix encodes attributed origin, paired with an arbitrary uppercase codeword.

Recorded Future Insikt Group

index ↗
  • Byzantine CandorU.S. government designator disclosed in leaked diplomatic cables

Colour prefix encodes attributed origin (RedXxxx = China, BlueXxxx = Russia). TAG-## ('Threat Activity Group') is a provisional designator for clusters pending attribution.

Kaspersky GReAT

index ↗
  • Comment Group

Descriptive names, often coined from a distinctive string or artifact in the toolset.

Symantec (Broadcom)

index ↗
  • Comment Crew

Insect, animal, and plant names assigned in the order clusters were first identified.

CISA / NSA / FBI

index ↗
  • PLA Unit 61398

U.S. government advisories generally reference groups by the most common industry name plus the attributed unit. Joint advisories are the authoritative source for unit-level attribution.

Targeting

Target geography

United StatesUnited KingdomCanadaIsraelJapanFranceSwitzerland

Tools & malware

Custom tooling is a strong clustering signal; shared and commodity tooling is not.

Custom / bespoke

WEBC2backdoor

Family of minimal backdoors retrieving commands hidden in HTML comments on attacker-controlled web pages — the origin of the 'Comment Crew' name.

GLOOXMAILbackdoor

Backdoor communicating over the Jabber/XMPP protocol via Google Talk infrastructure.

Custom FTP exfiltrationutility

Scripted bulk transfer of archived intellectual property to attacker-controlled servers.

Shared, commodity & living-off-the-land

HTRANutility

Connection-bouncing proxy tool used to relay traffic through intermediate hops and obscure origin.

Poison Ivybackdoor

Widely available RAT used alongside custom tooling.

Mimikatz / cachedumplotl

Credential extraction from memory and cached domain logons.

Exploited vulnerabilities

Filtered on the date this actor was first reported exploiting the flaw — not the CVE's publication date.

CVEUsage by APT1
CVE-2012-0158KEV8.81 May 2012MSCOMCTL buffer overflow embedded in lure documents — the workhorse exploit of the period, used by nearly every espionage group operating between 2012 and 2016.SRCMandiant

Actors sharing exploited CVEs

Kill chain

How this actor moves through an intrusion, stage by stage, titled by ATT&CK tactic. Read left to right.

7 stages · 9 techniques
  1. 02

    Persistence

    1 technique·derived

    Average dwell time of 356 days; longest documented was 1,764 days.

Scroll horizontally · characteristic chain across documented operations, not a single incident

MITRE ATT&CK techniques

Grouped in kill-chain order.

Open in Navigator ↗
9 techniques across 7 tactics · 7 with actor-specific notes

Initial Access

1

Persistence

1

Credential Access

1

Lateral Movement

1

Collection

2

Command and Control

2

Exfiltration

1

Campaign timeline

  1. landmark

    Mandiant APT1 Disclosure

    The first public attribution of a hacking campaign to a specific foreign military unit, with evidence. Mandiant identified PLA Unit 61398, located it to a facility in Shanghai's Pudong district, documented 141 victims across 20 industries, and profiled three individual operators — creating the modern threat intelligence industry in the process.

    CVE-2012-0158ManufacturingAerospaceEnergyTechnology

Known to work with

Relationship type and confidence stated explicitly — 'related' without qualification is not an assessment.

Primary-source reporting

Curated links to the reports that established what is known about this group.