Reconnaissance
1 technique·derived
Continuous scanning of target networks for newly exposed or end-of-life services.
MSS Hainan bureau running maritime and naval technology collection — and among the fastest actors at weaponising new vulnerabilities.
ATTRIBUTED TOChina › Ministry of State Security (MSS) — Hainan State Security Department › Hainan Xiandun Technology Development Co. (front company)
APT40 conducts maritime-focused collection aligned with China's naval modernisation and South China Sea claims. Its targeting is unusually coherent: naval engineering firms, universities conducting undersea and marine research, port and shipping operators, and the defence contractors supplying submarine and autonomous vehicle technology.
The group's operational signature is speed. An August 2024 advisory led by the Australian Signals Directorate and co-sealed by eight countries highlighted its ability to weaponise proof-of-concept exploits for new vulnerabilities within hours of public release — repeatedly reaching targets faster than those targets could patch. It complements this with persistent scanning for end-of-life and unmanaged internet-facing devices, and heavy use of compromised small-office routers as operational relays.
In July 2021 the U.S. Department of Justice indicted four individuals: three officers of the Hainan State Security Department and one contractor, operating through the front company Hainan Xiandun Technology Development Co. The indictment describes a front company that ran genuine job advertisements and even hired translators to process stolen material.
Down to the named unit where public evidence supports it.
Four individuals were indicted by the U.S. Department of Justice in July 2021: HSSD officers Ding Xiaoyang, Cheng Qingmin, and Zhu Yunmin, and contractor Wu Shurong. The indictment establishes Hainan Xiandun Technology Development Co. as a front for the Hainan State Security Department, a provincial arm of the MSS, and describes a 2011–2018 campaign against targets in at least a dozen countries. The attribution was issued alongside a coordinated statement from the EU, UK, NATO, and other allies.
Attributing sources
12 designators across 9 organisations.
Assigns a stable Gxxxx group ID and adopts the most widely used public name. Deliberately conservative — MITRE merges clusters only when public reporting supports it.
Weather-event family encodes the attributed origin; the adjective is arbitrary. Renamed from the older element taxonomy (STRONTIUM, NOBELIUM, HAFNIUM) in April 2023. 'Storm-####' is a temporary designator for a cluster still in development.
Animal denotes attributed nation-state or motive; the adjective distinguishes clusters. The original public adversary taxonomy, in use since 2012.
APTxx for state-nexus espionage, FINxx for financially motivated, UNCxxxx ('uncategorized') for clusters not yet graduated to a named group. Many UNC numbers are later merged into an APT/FIN designator.
Metal prefix encodes attributed origin, paired with an arbitrary uppercase codeword.
Colour prefix encodes attributed origin (RedXxxx = China, BlueXxxx = Russia). TAG-## ('Threat Activity Group') is a provisional designator for clusters pending attribution.
Descriptive names, often coined from a distinctive string or artifact in the toolset.
U.S. government advisories generally reference groups by the most common industry name plus the attributed unit. Joint advisories are the authoritative source for unit-level attribution.
Target sectors
Target geography
Custom tooling is a strong clustering signal; shared and commodity tooling is not.
Custom / bespoke
Long-lived implant family with Windows and Linux variants, shared across several Chinese groups.
Malpedia ↗Command-line reconnaissance tool for host and network enumeration inside victim environments.
Backdoor delivered via web-based exploitation, supporting file transfer and shell access.
Malpedia ↗Modular backdoors used for durable access to engineering and research networks.
Shared, commodity & living-off-the-land
End-of-life and unpatched small-office devices used as operational relay infrastructure in victim geographies.
Deployed rapidly to internet-facing applications following exploitation of newly disclosed vulnerabilities.
Filtered on the date this actor was first reported exploiting the flaw — not the CVE's publication date.
| CVE | Product | Usage by APT40 | ||
|---|---|---|---|---|
| CVE-2022-26134KEVransomware | 9.8 | Confluence Server / Data CenterAtlassian | 5 Jun 2022 | Atlassian Confluence OGNL injection weaponised within days of disclosure against research and government targets.SRCASD / CISA and partners ↗ |
| CVE-2021-44228KEVransomware | 10.0 | Apache Log4j2Apache | 1 Dec 2021 | Log4Shell exploited across internet-facing Java applications immediately following disclosure.SRCASD / CISA and partners ↗ |
| CVE-2021-31207 | — | — | 1 Aug 2021 | ProxyShell component exploited against Exchange servers for initial access to targeted organisations.SRCASD / CISA and partners ↗ |
| CVE-2021-26855KEVransomware | 9.8 | Microsoft Exchange ServerMicrosoft | 1 Mar 2021 | ProxyLogon exploited following public disclosure, alongside other Chinese groups.SRCASD / CISA and partners ↗ |
| CVE-2019-19781KEVransomware | 9.8 | Citrix ADC / GatewayCitrix | 1 Jan 2020 | Citrix ADC traversal exploited rapidly after disclosure for perimeter access.SRCASD / CISA and partners ↗ |
| CVE-2017-11882KEVransomware | 7.8 | Microsoft OfficeMicrosoft | 1 Jan 2018 | Equation Editor exploit in maritime- and defence-themed lure documents.SRCProofpoint ↗ |
Actors sharing exploited CVEs
How this actor moves through an intrusion, stage by stage, titled by ATT&CK tactic. Read left to right.
1 technique·derived
Continuous scanning of target networks for newly exposed or end-of-life services.
1 technique·derived
SOHO router relays to blend C2 with local traffic.
2 techniques·derived
Weaponises public proof-of-concept exploits within hours of release.
2 techniques·derived
Web Shell, Valid Accounts.
1 technique·derived
LSASS Memory.
2 techniques·derived
Research repositories and engineering document stores.
1 technique·derived
Exfiltration Over Unencrypted Non-C2 Protocol.
Scroll horizontally · characteristic chain across documented operations, not a single incident
Grouped in kill-chain order.
Continuous scanning of target networks for newly exposed or end-of-life services
SOHO router relays to blend C2 with local traffic
Weaponises public proof-of-concept exploits within hours of release
Research repositories and engineering document stores
A sustained pattern of weaponising public proof-of-concept exploits within hours of release, repeatedly reaching targets faster than they could patch. Documented in a 2024 advisory led by the Australian Signals Directorate and co-sealed by eight countries.
Relationship type and confidence stated explicitly — 'related' without qualification is not an assessment.
Both MSS-aligned contractor operations with distinct regional taskings.
Shared preference for compromised SOHO routers as in-country operational relays.
Both provincial MSS bureau operations run through named front companies.
Curated links to the reports that established what is known about this group.