APT30
APT30 is a threat group suspected to be associated with the Chinese government. While Naikon shares some characteristics with APT30, the two groups do not appear to be exact matches
APT30 is a China-linked nation-state threat group targeting government sectors.
APT30 is a nation-state cyber threat group suspected to be linked to China. It primarily targets the government sector in the United States, South Korea, Saudi Arabia, Thailand, Vietnam, Malaysia, and India. The group uses spearphishing attachments for initial access and deploys custom malware tools like SHIPSHAPE, BACKSPACE, and FLASHFLOOD. Defenders should focus on email security, block suspicious attachments, and monitor for the listed malware signatures.
APT30 is a threat group suspected to be associated with the Chinese government. While Naikon shares some characteristics with APT30, the two groups do not appear to be exact matches
Monitor email attachments and educate users about spearphishing.
Monitor and block the execution of unknown or malicious files.
APT30 primarily targets the government sector in the United States, South Korea, Saudi Arabia, Thailand, Vietnam, Malaysia, and India.
APT30 uses spearphishing attachments for initial access.
Every claim on this page is drawn from the cited source (MISP Galaxy, MITRE ATT&CK, ransomware.live) — no attribution is invented.