Skip to content
ChinaState-SponsoredActiveMITRE G0065Malpedia ↗

APT40

MSS Hainan bureau running maritime and naval technology collection — and among the fastest actors at weaponising new vulnerabilities.

ATTRIBUTED TOChina › Ministry of State Security (MSS) — Hainan State Security Department › Hainan Xiandun Technology Development Co. (front company)

Open MITRE Navigator layer ↗Download profile JSON
Active
2009–present
Motivation
Espionage, IP Theft
Aliases
12
Exploited CVEs
6
ATT&CK techniques
10
Cited sources
12

Overview

APT40 conducts maritime-focused collection aligned with China's naval modernisation and South China Sea claims. Its targeting is unusually coherent: naval engineering firms, universities conducting undersea and marine research, port and shipping operators, and the defence contractors supplying submarine and autonomous vehicle technology.

The group's operational signature is speed. An August 2024 advisory led by the Australian Signals Directorate and co-sealed by eight countries highlighted its ability to weaponise proof-of-concept exploits for new vulnerabilities within hours of public release — repeatedly reaching targets faster than those targets could patch. It complements this with persistent scanning for end-of-life and unmanaged internet-facing devices, and heavy use of compromised small-office routers as operational relays.

In July 2021 the U.S. Department of Justice indicted four individuals: three officers of the Hainan State Security Department and one contractor, operating through the front company Hainan Xiandun Technology Development Co. The indictment describes a front company that ran genuine job advertisements and even hired translators to process stolen material.

Attribution

Down to the named unit where public evidence supports it.

ChinaMinistry of State Security (MSS) — Hainan State Security DepartmentHainan Xiandun Technology Development Co. (front company)Confirmed

Four individuals were indicted by the U.S. Department of Justice in July 2021: HSSD officers Ding Xiaoyang, Cheng Qingmin, and Zhu Yunmin, and contractor Wu Shurong. The indictment establishes Hainan Xiandun Technology Development Co. as a front for the Hainan State Security Department, a provincial arm of the MSS, and describes a 2011–2018 campaign against targets in at least a dozen countries. The attribution was issued alongside a coordinated statement from the EU, UK, NATO, and other allies.

Attributing sources

Cross-vendor naming crosswalk

12 designators across 9 organisations.

MITRE ATT&CK

index ↗
  • APT40

Assigns a stable Gxxxx group ID and adopts the most widely used public name. Deliberately conservative — MITRE merges clusters only when public reporting supports it.

Microsoft Threat Intelligence

index ↗
  • Gingham TyphoonFormerly GADOLINIUM
  • GADOLINIUMRetired designator

Weather-event family encodes the attributed origin; the adjective is arbitrary. Renamed from the older element taxonomy (STRONTIUM, NOBELIUM, HAFNIUM) in April 2023. 'Storm-####' is a temporary designator for a cluster still in development.

CrowdStrike

index ↗
  • Kryptonite Panda

Animal denotes attributed nation-state or motive; the adjective distinguishes clusters. The original public adversary taxonomy, in use since 2012.

Mandiant / Google Threat Intelligence

index ↗
  • APT40
  • TEMP.PeriscopeEarlier Mandiant designator
  • TEMP.JumperEarlier Mandiant designator

APTxx for state-nexus espionage, FINxx for financially motivated, UNCxxxx ('uncategorized') for clusters not yet graduated to a named group. Many UNC numbers are later merged into an APT/FIN designator.

Secureworks CTU

index ↗
  • BRONZE MOHAWK

Metal prefix encodes attributed origin, paired with an arbitrary uppercase codeword.

Recorded Future Insikt Group

index ↗
  • ISLANDDREAMS

Colour prefix encodes attributed origin (RedXxxx = China, BlueXxxx = Russia). TAG-## ('Threat Activity Group') is a provisional designator for clusters pending attribution.

Kaspersky GReAT

index ↗
  • MUDCARP

Descriptive names, often coined from a distinctive string or artifact in the toolset.

Proofpoint

index ↗
  • Leviathan

TA### ('Threat Actor'), numbered sequentially in order of first tracking.

CISA / NSA / FBI

index ↗
  • APT40 / Hainan State Security Department

U.S. government advisories generally reference groups by the most common industry name plus the attributed unit. Joint advisories are the authoritative source for unit-level attribution.

Targeting

Target geography

AustraliaUnited StatesUnited KingdomCambodiaMalaysiaPhilippinesNorwayGermanySaudi Arabia

Tools & malware

Custom tooling is a strong clustering signal; shared and commodity tooling is not.

Custom / bespoke

Derusbibackdoor

Long-lived implant family with Windows and Linux variants, shared across several Chinese groups.

Malpedia ↗
MURKYTOPutility

Command-line reconnaissance tool for host and network enumeration inside victim environments.

BADFLICKbackdoor

Backdoor delivered via web-based exploitation, supporting file transfer and shell access.

Malpedia ↗
PHOTO / Derusbi variantsbackdoor

Modular backdoors used for durable access to engineering and research networks.

Shared, commodity & living-off-the-land

Compromised SOHO routersutility

End-of-life and unpatched small-office devices used as operational relay infrastructure in victim geographies.

Web shellsutility

Deployed rapidly to internet-facing applications following exploitation of newly disclosed vulnerabilities.

Exploited vulnerabilities

Filtered on the date this actor was first reported exploiting the flaw — not the CVE's publication date.

CVEUsage by APT40
CVE-2022-26134KEVransomware9.85 Jun 2022Atlassian Confluence OGNL injection weaponised within days of disclosure against research and government targets.SRCASD / CISA and partners
CVE-2021-44228KEVransomware10.01 Dec 2021Log4Shell exploited across internet-facing Java applications immediately following disclosure.SRCASD / CISA and partners
CVE-2021-312071 Aug 2021ProxyShell component exploited against Exchange servers for initial access to targeted organisations.SRCASD / CISA and partners
CVE-2021-26855KEVransomware9.81 Mar 2021ProxyLogon exploited following public disclosure, alongside other Chinese groups.SRCASD / CISA and partners
CVE-2019-19781KEVransomware9.81 Jan 2020Citrix ADC traversal exploited rapidly after disclosure for perimeter access.SRCASD / CISA and partners
CVE-2017-11882KEVransomware7.81 Jan 2018Equation Editor exploit in maritime- and defence-themed lure documents.SRCProofpoint

Kill chain

How this actor moves through an intrusion, stage by stage, titled by ATT&CK tactic. Read left to right.

7 stages · 10 techniques

Scroll horizontally · characteristic chain across documented operations, not a single incident

MITRE ATT&CK techniques

Grouped in kill-chain order.

Open in Navigator ↗
10 techniques across 7 tactics · 4 with actor-specific notes

Reconnaissance

1

Resource Development

1

Initial Access

2

Collection

2

Campaign timeline

  1. Rapid Exploitation of New Vulnerabilities

    A sustained pattern of weaponising public proof-of-concept exploits within hours of release, repeatedly reaching targets faster than they could patch. Documented in a 2024 advisory led by the Australian Signals Directorate and co-sealed by eight countries.

Known to work with

Relationship type and confidence stated explicitly — 'related' without qualification is not an assessment.

Primary-source reporting

Curated links to the reports that established what is known about this group.