Initial Access
1 technique·derived
Straightforward attachments with industry-relevant filenames.
PLA Unit 61398. The first threat group ever publicly attributed to a specific military unit — the report that created the modern threat intelligence industry.
ATTRIBUTED TOChina › People's Liberation Army — General Staff Department, 3rd Department, 2nd Bureau › Unit 61398
APT1 matters less for what it did than for what naming it changed.
Mandiant's February 2013 report was the first time a private company publicly attributed a hacking campaign to a specific military unit of a foreign government, with evidence. It identified People's Liberation Army Unit 61398 of the 2nd Bureau, 3rd Department of the General Staff Department, located the operation in a purpose-built twelve-storey facility on Datong Road in the Pudong district of Shanghai, documented 141 victims across 20 industries, and profiled three individual operators by handle — "UglyGorilla," "DOTA," and "SuperHard."
The tradecraft itself was unremarkable. Operators used spearphishing with straightforward attachments, a large but pedestrian toolset, and — critically — poor operational security, frequently connecting to victim infrastructure directly from Shanghai IP ranges. The volume was industrial: hundreds of terabytes of intellectual property, stolen methodically across industries the PRC's Five-Year Plans had designated as strategic priorities.
In May 2014 the U.S. Department of Justice indicted five Unit 61398 officers by name — the first criminal charges ever brought against state actors for cyber-enabled economic espionage.
The group ceased its documented activity following exposure. Its practical successors are the MSS provincial bureaus and contractor firms — APT10, APT40, APT31 — which conduct the same mission with far better operational security and a layer of plausible deniability between the state and the keyboard.
Down to the named unit where public evidence supports it.
Military Unit Cover Designator 61398, Datong Road, Gaoqiao, Pudong New Area, Shanghai
Attributed to PLA Unit 61398 by Mandiant in February 2013 on the basis of infrastructure analysis, operator persona tracking, and geolocation of activity to a single Shanghai facility. The U.S. Department of Justice indicted five Unit 61398 officers in May 2014 — Wang Dong, Sun Kailiang, Wen Xinyu, Huang Zhenyu, and Gu Chunhui — for economic espionage against U.S. steel, solar, and nuclear power companies. These were the first criminal charges brought against state actors for cyber economic espionage.
Attributing sources
8 designators across 8 organisations.
Assigns a stable Gxxxx group ID and adopts the most widely used public name. Deliberately conservative — MITRE merges clusters only when public reporting supports it.
Animal denotes attributed nation-state or motive; the adjective distinguishes clusters. The original public adversary taxonomy, in use since 2012.
APTxx for state-nexus espionage, FINxx for financially motivated, UNCxxxx ('uncategorized') for clusters not yet graduated to a named group. Many UNC numbers are later merged into an APT/FIN designator.
Metal prefix encodes attributed origin, paired with an arbitrary uppercase codeword.
Colour prefix encodes attributed origin (RedXxxx = China, BlueXxxx = Russia). TAG-## ('Threat Activity Group') is a provisional designator for clusters pending attribution.
Descriptive names, often coined from a distinctive string or artifact in the toolset.
Insect, animal, and plant names assigned in the order clusters were first identified.
U.S. government advisories generally reference groups by the most common industry name plus the attributed unit. Joint advisories are the authoritative source for unit-level attribution.
Target sectors
Target geography
Custom tooling is a strong clustering signal; shared and commodity tooling is not.
Custom / bespoke
Family of minimal backdoors retrieving commands hidden in HTML comments on attacker-controlled web pages — the origin of the 'Comment Crew' name.
Backdoor communicating over the Jabber/XMPP protocol via Google Talk infrastructure.
Scripted bulk transfer of archived intellectual property to attacker-controlled servers.
Shared, commodity & living-off-the-land
Connection-bouncing proxy tool used to relay traffic through intermediate hops and obscure origin.
Widely available RAT used alongside custom tooling.
Credential extraction from memory and cached domain logons.
Filtered on the date this actor was first reported exploiting the flaw — not the CVE's publication date.
| CVE | Product | Usage by APT1 | ||
|---|---|---|---|---|
| CVE-2012-0158KEV | 8.8 | Microsoft OfficeMicrosoft | 1 May 2012 | MSCOMCTL buffer overflow embedded in lure documents — the workhorse exploit of the period, used by nearly every espionage group operating between 2012 and 2016.SRCMandiant ↗ |
Actors sharing exploited CVEs
How this actor moves through an intrusion, stage by stage, titled by ATT&CK tactic. Read left to right.
1 technique·derived
Straightforward attachments with industry-relevant filenames.
1 technique·derived
Average dwell time of 356 days; longest documented was 1,764 days.
1 technique·derived
OS Credential Dumping.
1 technique·derived
RDP from Shanghai IP ranges — poor operational security that enabled attribution.
2 techniques·derived
RAR archives split for transfer, staged before bulk exfiltration.
2 techniques·derived
Commands embedded in HTML comments on legitimate web pages. HTRAN relays.
1 technique·derived
FTP transfer of hundreds of terabytes of intellectual property.
Scroll horizontally · characteristic chain across documented operations, not a single incident
Grouped in kill-chain order.
Straightforward attachments with industry-relevant filenames
Average dwell time of 356 days; longest documented was 1,764 days
RDP from Shanghai IP ranges — poor operational security that enabled attribution
RAR archives split for transfer, staged before bulk exfiltration
Commands embedded in HTML comments on legitimate web pages
HTRAN relays
FTP transfer of hundreds of terabytes of intellectual property
The first public attribution of a hacking campaign to a specific foreign military unit, with evidence. Mandiant identified PLA Unit 61398, located it to a facility in Shanghai's Pudong district, documented 141 victims across 20 industries, and profiled three individual operators — creating the modern threat intelligence industry in the process.
Relationship type and confidence stated explicitly — 'related' without qualification is not an assessment.
Not a direct lineage. Represents the structural shift after the 2015 PLA reforms, from military units to MSS provincial bureaus and contractor firms.
Same strategic mission of intellectual property theft, executed through a contractor model with far better operational security.
Curated links to the reports that established what is known about this group.