APT40 — what to detect, and what we don’t know.

Maritime and research targets, Saudi Arabia included.

50 techniques 14 detection behaviours 17 tools mapped Saudi Arabia

Also tracked as  TEMP.Periscope · TEMP.Jumper · Leviathan · BRONZE MOHAWK · GADOLINIUM · KRYPTONITE PANDA · G0065 · ATK29 · TA423 · Red Ladon · ITG09 · MUDCARP

Attributed to
CN China
Gulf victimology
1 Saudi Arabia
Techniques
50 across 13 tactics
Tooling
17 6 actor-specific · 11 commodity
Reporting
3 2 outlets · 31 research hosts

Summary

The short version

APT40 is a threat actor attributed to China, assessed as espionage-motivated. Its recorded targeting runs to government, private sector across 13 countries in the open reporting we hold — Saudi Arabia among them.

Across 50 attributed ATT&CK techniques we resolve 14 distinct behaviours — the things they do that a detection can be written against. The two that account for most of their observed tradecraft are valid account abuse or account creation and persistence pointing into world-writable staging. Their toolkit is 17 named items: 6 we see only in this actor's reporting and 11 commodity or dual-use. That ratio is the point — the first group is what identifies them, the second is what they share with every other group and with red teams.

For a Gulf defender the relevant line is the victimology: Saudi Arabia appear in the reporting behind this record. That is evidence of past targeting, not a forecast, and it is drawn from what vendors chose to publish — an actor working quietly in a market nobody reports on looks identical to one that is absent.

As MITRE describes them: “Leviathan is an espionage actor targeting organizations and high-value targets in defense and government. Active since at least 2014, this actor has long-standing interest in maritime industries, naval defense contractors, and associated research institutions in the United States and Western Europe.” — MITRE ATT&CK, CC BY 4.0.

On the name. “APT40” labels a cluster of related activity tracked under one name — not a verified organisation. Whether one team, several contractors or a rotating cast sits behind it is not something this record establishes, and the vendor names below are separate groupings that only mostly overlap.

02 — The detection plan

What to detect, ranked by what survives their retooling

Most actor profiles hand you indicators that expire in days. These are the behaviours the actor cannot drop without changing how they operate, each with the reason it holds. Weight is our own: how much of the actor's observed tradecraft the behaviour accounts for.

D2

Persistence pointing into world-writable staging

Tier 1–2

The persistence mechanism and the directory it points at both outlive the payload. The discriminator is the TARGET PATH, not the task or key name, which the actor can change freely.

8 techniques · weight 5

D3

Credential access against LSASS

Tier 3–5

Few legitimate processes read LSASS memory, so precision is high in most estates once the agents that do are excluded.

2 techniques · weight 5

D4

Web shell written into a served directory

Tier 3

A script file appearing under a web root outside a deployment window is close to a binary signal, and it catches the entry vector rather than the aftermath.

2 techniques · weight 5

D5

User-facing application spawning an interpreter

Tier 3

The delivery wrapper changes constantly; an office, archive or browser process parenting a shell is the same shape across all of them.

8 techniques · weight 5

D1

Sanctioned SaaS platform as command or exfil channel

Tier 5–6

Defeats egress-domain control outright — the destination is a platform the estate already permits, so no blocklist and no TLD heuristic will see it.

7 techniques · weight 4

D6

Encoded or obfuscated interpreter invocation

Tier 3

The command-line SHAPE — the flag combination, not the payload — is stable for months to years and cheap to match.

8 techniques · weight 4

D12

Execution brokered through WMI or a native API

Tier 3

Chosen to avoid a shell, so command-line rules miss it entirely. The broker is a stable choice; what it runs is not.

6 techniques · weight 4

D7

Living-off-the-land download of a second stage

Tier 5

The set of system binaries that can fetch a file is small and changes with the OS, not with the actor.

5 techniques · weight 3

D8

Remote service or share used to move laterally

Tier 3

Lateral movement leaves a service-creation or admin-share write that is the same regardless of the tool that made it.

6 techniques · weight 3

D9

Collection staged into an archive before egress

Tier 3

Staging is a step the actor cannot skip, and it happens before the data leaves — the last cheap place to catch it.

7 techniques · weight 3

D10

Exploitation of an internet-facing service

Context

Not a durable behavioural signature but the entry vector for a large public estate — worth an exposure control even where the detection is weak.

3 techniques · weight 3

D11

Protocol tunnelling or an internal proxy hop

Tier 5

The tunneller is a tool choice that persists for months, and the traffic shape is visible even when the payload is not.

8 techniques · weight 3

D13

Valid account abuse or account creation

Tier 5

Produces no malware event at all — the only trace is in identity telemetry, which is why an endpoint-only programme has a blind spot exactly here.

10 techniques · weight 3

D14

Beaconing to attacker infrastructure over web protocols

Tier 6–7

The URI shape and cadence are cheap to match and hold for weeks to months — but the destination itself rotates in days, so match the pattern rather than the host.

7 techniques · weight 3

How to score it

No single behaviour here is worth waking someone. Summed weights of 6 on one host inside a window is an alert; 10 is an incident. The pair that most reliably means this actor rather than commodity crime is Persistence pointing into world-writable staging + Credential access against LSASS — seen together, treat as an incident regardless of total.

03 — Tooling

17 named tools, and what each is for

Purpose is derived, not asserted: each tool's own ATT&CK techniques are resolved to tactics, and the tactics it spends most of its techniques in are what it is for.

Actor-specific means we have no record of it outside this actor's reporting — those are the names that identify them. Commodity covers everything sold, published or shared: Cobalt Strike and Brute Ratel are licensed red-team software every pentester owns, Mimikatz and Impacket are public, and backdoors like ShadowPad circulate between unrelated groups. Finding a commodity tool tells you far less, which is exactly why the split is drawn. ATT&CK's own “malware vs tool” type answers a different question — whether the software is malicious — so it is not used for this.

Actor-specific — 6 items

Orz Actor-specific

Network reconnaissance and evading defences.

S0229  ·  13 techniques  ·  Discovery, Stealth, Command and Control
NanHaiShu Actor-specific

Staying resident and network reconnaissance.

S0228  ·  12 techniques  ·  Persistence, Discovery, Stealth
BADFLICK Actor-specific

Gathering data and first access.

S0642  ·  10 techniques  ·  Collection, Initial Access, Discovery
MURKYTOP Actor-specific

Network reconnaissance and running code.

S0233  ·  9 techniques  ·  Discovery, Execution, Stealth
BLACKCOFFEE Actor-specific

Remote control and network reconnaissance.

S0069  ·  7 techniques  ·  Command and Control, Discovery, Execution
HOMEFRY Actor-specific

Credential theft and running code.

S0232  ·  3 techniques  ·  Credential Access, Execution, Stealth

Commodity and dual-use — 11 items

Empire Commodity

Credential theft and gathering data.

S0363  ·  73 techniques  ·  Credential Access, Collection, Persistence
Cobalt Strike Commodity

Moving between hosts and gathering data.

S0154  ·  73 techniques  ·  Lateral Movement, Collection, Privilege Escalation
PowerSploit Commodity

Credential theft and gathering data.

S0194  ·  28 techniques  ·  Credential Access, Collection, Persistence
gh0st RAT Commodity

Gathering data and staying resident.

S0032  ·  24 techniques  ·  Collection, Persistence, Command and Control
Derusbi Commodity

Gathering data and network reconnaissance.

S0021  ·  18 techniques  ·  Collection, Discovery, Command and Control
Net Commodity

Staying resident and moving between hosts.

S0039  ·  16 techniques  ·  Persistence, Lateral Movement, Discovery
China Chopper Commodity

Gathering data and credential theft.

S0020  ·  10 techniques  ·  Collection, Credential Access, Persistence
BITSAdmin Commodity

Moving data out and moving between hosts.

S0190  ·  4 techniques  ·  Exfiltration, Lateral Movement, Command and Control
Tor Commodity

Remote control.

S0183  ·  2 techniques  ·  Command and Control

Credential theft.

S0005  ·  1 techniques  ·  Credential Access
at Commodity

Running code.

S0110  ·  1 techniques  ·  Execution
No data

File hashes for APT40’s own tooling

We hold none. Our corpus carries 9,780 hashes, but they come from live feeds covering current commodity campaigns — not the decade-old actor-specific backdoors in the list above. ATT&CK itself publishes no sample hashes; it is a technique knowledge base. Where a sample would have to come from a third party’s family tag rather than from this actor’s reporting, we leave the row empty instead of implying an attribution we cannot support.

File hashes — commodity families — 18 held

⚠ These are samples of tools this actor is reported to use, not samples tied to this actor. Cobalt Strike and China Chopper are used by hundreds of groups and by red teams; a match here is evidence about the tool, not about APT40. Published because a hunt starting point is still worth having, labelled so it cannot be mistaken for attribution.

HashTypeFamilyFirst seen
1c948822cb57763c1d343542ee4ade212d8f4fbbsha1China Chopper2026-07-07
89cb9c926e136c54011f3e0792b4a28cmd5China Chopper2026-07-07
6f336f372c5a642b57413363265e7d7emd5China Chopper2026-07-07
f3570bb6e0f9c695d48f89f043380b43831dd0f6fe79b16eda2a3ffd9fd7ad16sha256China Chopper2026-07-07
9f33095a24471bed55ce11803e4ebbed5118bfb5d3861baf1c8214efcd9e7de6sha256China Chopper2026-07-07
35e0b22139fb27d2c9721aedf5770d893423bf029e1f56be92485ff8fce210f3sha256China Chopper2026-07-07
fe11b199ada23d5ac25efc4215e67f4ff617ccb4d429eb64412072687367ca1csha256Cobalt Strike2026-06-22
ed7087e3afba4b320bdf04f32d3a6c567effd3d18a97682968e567000e70b335sha256Cobalt Strike2026-06-22
eb14d9e35a3bf0a933297f861bee0be9e6b9061fe4573a81ac92b71d55b6474fsha256Cobalt Strike2026-06-22
e7aff6a55a7866776272d9913dfbf9d7db33fc9de6aced22f2a195feebb0e85fsha256Cobalt Strike2026-06-22
cd99e83d241cfbb41bfcd0bc622a87d16268e710ca7d736d0c5f44774e0056e2sha256Cobalt Strike2026-06-22
c937eca7c4c9b98df9257d986e666d25411aac5fa39d21f7018dd2e1663f0c76sha256Cobalt Strike2026-06-22

04 — Coverage, honestly counted

Where the 50 techniques actually go

Of the techniques attributed to APT40, 37 fold into the detection plan above, 10 describe preparation you cannot see from inside your network, and 3 are uncatalogued — we have not yet placed them. That last number is published on purpose; it is the honest size of the gap.

Stealth9
Resource Development8
Execution7
Command and Control4
Initial Access4
Persistence4
Collection3
Lateral Movement3
Credential Access2
Exfiltration2
Reconnaissance2
Defense Impairment1
Privilege Escalation1

05 — The chain

The order it happens in

The same techniques as above, sequenced. Useful for deciding where to spend a detection: the earlier a tactic sits, the more of the intrusion you still get to prevent.

01
Reconnaissance
2 techniques
02
Resource Development
8 techniques
03
Initial Access
4 techniques
04
Execution
7 techniques
05
Persistence
4 techniques
06
Privilege Escalation
1 technique
07
Credential Access
2 techniques
08
Lateral Movement
3 techniques
09
Collection
3 techniques
10
Command and Control
4 techniques
11
Exfiltration
2 techniques
12
Stealth
9 techniques
13
Defense Impairment
1 technique

06 — Tradecraft artefacts

Concrete strings, each with the report it came from

Pulled from primary vendor research and kept attributed. These are hunt starting points, not detections — a path an actor used once is worth a query, not a rule.

ArtefactKind First reported byDate
%programdata%\Microsoft\DeviceSync\ file path Google TAG 2023-10-18
%temp%\{random_directory}\poc.png_ file path Google TAG 2023-10-18

07 — Sourcing, graded

Who told us, and how much that is worth

NATO Admiralty grading. The letter is the source's reliability, the number the credibility of the claim. We separate primary vendor research from outlets reporting on it, because ten articles derived from one report is one report.

GradeSourceBasis
B2MITRE actor record44 references across 31 distinct research hosts
B2Recorded Future2 items — primary vendor research
C3Google TAG1 item — reporting on other vendors' research
—Estate telemetryno data — absent, not negative

3 items · 2 outlets · 67% of reporting traces to a single outlet

08 — What we do not know

The gaps, published

Every vendor profile has these. Most omit them, which leaves you unable to tell a quiet actor from an unobserved one.

NO DATA

C2 URI fingerprints

No URI paths, headers or beacon sequences for any family we hold, and no URL indicators at all to derive them from — the indicator set is hashes, hosts and addresses.

NO DATA

Infrastructure

No domains are attributed to this actor in our holdings, so no naming convention, TLD preference or hosting pattern can be derived.

09 — Outlook

Forward judgements

Probability language is ICD 203. Likelihood and confidence are stated separately: how likely we think it is, and how good our basis is for thinking so.

Remains active
our newest reporting on this actor is from 2025-10-06, 348 days ago
LIKELYconf LOW
sanctioned SaaS platform as command or exfil channel continues
a tier-5–6 behaviour, which outlives the tooling that expresses it
VERY LIKELYconf MODERATE

10 — Primary sources

Every reference behind this record

44 of them. Published in full so the page can be checked rather than believed.

proofpoint.comhttps://www.proofpoint.com/us/threat-insight/post/leviathan-espionage-actor-spearphishes-maritimfireeye.comhttps://www.fireeye.com/blog/threat-research/2018/03/suspected-chinese-espionage-group-targetingcfr.orghttps://www.cfr.org/interactive/cyber-operations/apt-40fireeye.comhttps://www.fireeye.com/blog/threat-research/2019/03/apt40-examining-a-china-nexus-espionage-actrecordedfuture.comhttps://www.recordedfuture.com/chinese-threat-actor-tempperiscope/fireeye.comhttps://www.fireeye.com/blog/threat-research/2018/07/chinese-espionage-group-targets-cambodia-ahattack.mitre.orghttps://attack.mitre.org/groups/G0065/crowdstrike.comhttps://www.crowdstrike.com/resources/reports/2019-crowdstrike-global-threat-report/go.crowdstrike.comhttps://go.crowdstrike.com/rs/281-OBQ-266/images/Report2020CrowdStrikeGlobalThreatReport.pdfintrusiontruth.wordpress.comhttps://intrusiontruth.wordpress.com/2020/01/09/what-is-the-hainan-xiandun-technology-developmenintrusiontruth.wordpress.comhttps://intrusiontruth.wordpress.com/2020/01/10/who-is-mr-guintrusiontruth.wordpress.comhttps://intrusiontruth.wordpress.com/2020/01/13/who-else-works-for-this-cover-company-networkintrusiontruth.wordpress.comhttps://intrusiontruth.wordpress.com/2020/01/14/who-is-mr-dingintrusiontruth.wordpress.comhttps://intrusiontruth.wordpress.com/2020/01/15/hainan-xiandun-technology-company-is-apt40secureworks.comhttps://www.secureworks.com/research/threat-profiles/bronze-mohawkmycert.org.myhttps://www.mycert.org.my/portal/advisory?id=MA-774.022020elastic.cohttps://www.elastic.co/blog/advanced-techniques-used-in-malaysian-focused-apt-campaignmicrosoft.comhttps://www.microsoft.com/security/blog/2020/09/24/gadolinium-detecting-empires-cloud/justice.govhttps://www.justice.gov/opa/pr/four-chinese-nationals-working-ministry-state-security-charged-gljustice.govhttps://www.justice.gov/opa/press-release/file/1412916/downloadjustice.govhttps://www.justice.gov/opa/press-release/file/1412921/downloadus-cert.cisa.govhttps://us-cert.cisa.gov/ncas/alerts/aa21-200aus-cert.cisa.govhttps://us-cert.cisa.gov/ncas/alerts/aa21-200bcanada.cahttps://www.canada.ca/en/global-affairs/news/2021/07/statement-on-chinas-cyber-campaigns.htmlncsc.gov.ukhttps://www.ncsc.gov.uk/news/uk-allies-hold-chinese-state-responsible-for-pervasive-pattern-of-hgov.ukhttps://www.gov.uk/government/news/uk-and-allies-hold-chinese-state-responsible-for-a-pervasive-rnz.co.nzhttps://www.rnz.co.nz/news/political/447239/government-points-finger-at-china-over-cyber-attacksforeignminister.gov.auhttps://www.foreignminister.gov.au/minister/marise-payne/media-release/australia-joins-internatimofa.go.jphttps://www.mofa.go.jp/press/danwa/press6e_000312.htmlconsilium.europa.euhttps://www.consilium.europa.eu/en/press/press-releases/2021/07/19/declaration-by-the-high-repremandiant.comhttps://www.mandiant.com/resources/insights/apt-groupsquery.prod.cms.rt.microsoft.comhttps://query.prod.cms.rt.microsoft.com/cms/api/am/binary/RWMFIidecoded.avast.iohttps://decoded.avast.io/threatintel/outbreak-of-follina-in-australiaproofpoint.comhttps://www.proofpoint.com/us/blog/threat-insight/chasing-currents-espionage-south-china-seaaccenture.comhttps://www.accenture.com/_acnmedia/pdf-96/accenture-security-mudcarp.pdfblog.googlehttps://blog.google/threat-analysis-group/government-backed-actors-exploiting-winrar-vulnerabilicloud.google.comhttps://cloud.google.com/blog/topics/threat-intelligence/updated-cyber-threat-actor-naming-systeapt.etda.or.thhttps://apt.etda.or.th/cgi-bin/showcard.cgi?u=b106313a-d204-4d9f-866b-e750a98d0e06zdnet.comhttps://www.zdnet.com/article/malaysia-warns-of-chinese-hacking-campaign-targeting-government-prbeehive.govt.nzhttps://www.beehive.govt.nz/release/parliamentary-network-breached-prcintrusiontruth.wordpress.comhttps://intrusiontruth.wordpress.com/2020/01/09/what-is-the-hainan-xiandun-technology-developmenintrusiontruth.wordpress.comhttps://intrusiontruth.wordpress.com/2020/01/10/who-is-mr-gu/us-cert.cisa.govhttps://us-cert.cisa.gov/sites/default/files/publications/CSA_TTPs-of-Indicted-APT40-Actors-Associsa.govhttps://www.cisa.gov/news-events/cybersecurity-advisories/aa24-190a

Run it against your own estate

Which of these 14 behaviours do you already detect?

The library is the part we can publish. The platform runs the same detection plan against your own estate, tells you which of these behaviours you already cover, and retro-hunts the rest — on your hardware, with nothing leaving the building.

❯ ESC

THE TRACE · LOCAL INFERENCE · REASONING SHOWN STEP-BY-STEP

Try: “which of our vendors were hit by qilin” · “fortios exposure” · “what changed on our perimeter this week”