APT1
PLA Unit 61398 (Chinese: 61398部队, Pinyin: 61398 bùduì) is the Military Unit Cover Designator (MUCD)[1] of a People's Liberation Army advanced persistent threat unit that has been alleged to be a source of Chinese computer hacking attacks
APT1 is a China-linked cyber espionage group known for targeting government entities with PoisonIvy.
APT1, also known as Comment Panda, is a nation-state cyber espionage group attributed to China's People's Liberation Army Unit 61398. They target government and private sector entities primarily in the United States, Taiwan, and parts of Europe and Asia. The group commonly utilizes spearphishing attachments and links for initial access, followed by execution via Windows Command Shell, credential theft from LSASS Memory, and lateral movement through Pass the Hash and RDP; their arsenal includes malware like PoisonIvy and BISCUIT, along with tools such as Mimikatz and PsExec. Defenders should focus on filtering spearphishing emails, monitoring for LSASS memory access and anomalous RDP traffic, and implementing detection rules based on known indicators associated with this group.
PLA Unit 61398 (Chinese: 61398部队, Pinyin: 61398 bùduì) is the Military Unit Cover Designator (MUCD)[1] of a People's Liberation Army advanced persistent threat unit that has been alleged to be a source of Chinese computer hacking attacks
Monitor suspicious domain registrations and malware downloads to identify used domains and malware.
Monitor email content and user interaction to detect suspicious spearphishing attachments and links.
Monitor process creation and command line arguments to detect suspicious Windows Command Shell activity.
Monitor file system access to detect malicious files masquerading as legitimate resource names and locations.
Monitor access to LSASS process to detect attempts to obtain credentials from LSASS memory.
Monitor system and process queries to detect suspicious System Network Configuration Discovery and Process Discovery.
Monitor RDP connections and authentication attempts to detect suspicious RDP and Pass the Hash activity.
Monitor file system access and archiving utility usage to detect suspicious data collection and archiving.
APT1 is a nation-state group attributed to China's People's Liberation Army.
APT1's arsenal includes the PoisonIvy malware.
Every claim on this page is drawn from the cited source (MISP Galaxy, MITRE ATT&CK, ransomware.live) — no attribution is invented.