APT40 (also known as BRONZE MOHAWK (by
Secureworks), FEVERDREAM, G0065, Gadolinium (by
Microsoft
Microsoft Corporation is an American multinational corporation, multinational technology company, technology corporation producing Software, computer software, consumer electronics, personal computers, and related services headquartered at th ...
), GreenCrash, Hellsing (by
Kaspersky), Kryptonite Panda (by
Crowdstrike
CrowdStrike Holdings, Inc. is an American cybersecurity technology company based in Austin, Texas. It provides cloud workload and endpoint security, threat intelligence, and cyberattack response services. The company has been involved in inves ...
), Leviathan (by
Proofpoint),
MUDCARP, Periscope, Temp.Periscope, and Temp.Jumper) is an
advanced persistent threat
An advanced persistent threat (APT) is a stealthy threat actor, typically a nation state or state-sponsored group, which gains unauthorized access to a computer network and remains undetected for an extended period. In recent times, the term m ...
located in
Haikou
Haikou (; ), also spelled as Hoikow is the capital and most populous city of the Chinese province of Hainan. Haikou city is situated on the northern coast of Hainan, by the mouth of the Nandu River. The northern part of the city is on the ...
,
Hainan Province
Hainan (, ; ) is the smallest and southernmost province of the People's Republic of China (PRC), consisting of various islands in the South China Sea. , the largest and most populous island in China,The island of Taiwan, which is slight ...
,
People's Republic of China
China, officially the People's Republic of China (PRC), is a country in East Asia. It is the world's List of countries and dependencies by population, most populous country, with a Population of China, population exceeding 1.4 billion, sli ...
(PRC), and has been active since at least 2009. APT40 has targeted
governmental organizations
A government or state agency, sometimes an appointed commission, is a permanent or semi-permanent organization in the machinery of government that is responsible for the oversight and administration of specific functions, such as an administratio ...
, companies, and universities in a wide range of industries, including biomedical, robotics, and maritime research, across the
United States
The United States of America (U.S.A. or USA), commonly known as the United States (U.S. or US) or America, is a country primarily located in North America. It consists of 50 U.S. state, states, a Washington, D.C., federal district, five ma ...
,
Canada
Canada is a country in North America. Its ten provinces and three territories extend from the Atlantic Ocean to the Pacific Ocean and northward into the Arctic Ocean, covering over , making it the world's second-largest country by tota ...
,
Europe
Europe is a large peninsula conventionally considered a continent in its own right because of its great physical size and the weight of its history and traditions. Europe is also considered a subcontinent of Eurasia and it is located enti ...
, the
Middle East
The Middle East ( ar, الشرق الأوسط, ISO 233: ) is a geopolitical region commonly encompassing Arabia (including the Arabian Peninsula and Bahrain), Asia Minor (Asian part of Turkey except Hatay Province), East Thrace (Europ ...
, and the
South China Sea
The South China Sea is a marginal sea of the Western Pacific Ocean. It is bounded in the north by the shores of South China (hence the name), in the west by the Indochinese Peninsula, in the east by the islands of Taiwan and northwestern Phil ...
area, as well as industries included in China's
Belt and Road Initiative
The Belt and Road Initiative (BRI, or B&R), formerly known as One Belt One Road ( zh, link=no, 一带一路) or OBOR for short, is a global infrastructure development strategy adopted by the Chinese government in 2013 to invest in nearly 1 ...
.
APT40 is closely connected to
Hafnium
Hafnium is a chemical element with the symbol Hf and atomic number 72. A lustrous, silvery gray, tetravalent transition metal, hafnium chemically resembles zirconium and is found in many zirconium minerals. Its existence was predicted by D ...
.
Indictment
On July 19, 2021, the
U.S. Department of Justice (DOJ) unsealed an indictment against four APT40 cyber actors for their illicit computer network exploitation activities via front company Hainan Xiandun Technology Development Company.
See also
*
Cyberwarfare by China
Cyberwarfare by China is the aggregate of all combative activities in the cyberspace which are taken by organs of the People's Republic of China, including affiliated advanced persistent threat groups, against other countries.
Organization
Wh ...
*
Red Apollo
Red Apollo (also known as APT 10 (by Mandiant), MenuPass (by Fireeye), Stone Panda (by Crowdstrike), and POTASSIUM (by Microsoft)) is a Chinese state-sponsored cyberespionage group. A 2018 indictment by the United States Department of Just ...
References
Chinese advanced persistent threat groups
Espionage
Hacking (computer security)
Cyberwarfare
{{Hacking in the 2020s