A China-sponsored espionage actor known for targeting government and maritime sectors with spyware operations.
Analyst brief
APT40, also known as Leviathan, is a China-sponsored espionage actor active since at least 2014. It targets government entities, defense industries, naval contractors, and maritime research institutions primarily in the United States, Western Europe, and the Asia-Pacific region. Key TTPs include credential harvesting, spearphishing links for initial access, WMI and Cobalt Strike for execution and lateral movement, and cloud storage services for data exfiltration. Defenders should monitor for WMI abuse, LSASS credential dumping attempts, and suspicious data transfers to unauthorized cloud platforms.
APT40
TEMP.PeriscopeTEMP.JumperLeviathan
nation-state
Leviathan is an espionage actor targeting organizations and high-value targets in defense and government. Active since at least 2014, this actor has long-standing interest in maritime industries, naval defense contractors, and associated research institutions in the United States and Western Europe.
origin (suspected)
🇨🇳China· state-sponsoredattribution confidence: medium (50)
target countries (as stated by the source)
United StatesHong KongThe PhilippinesAsia Pacific Economic Cooperation
APT40 primarily targets government entities, defense industries, naval contractors, and maritime research institutions in the United States, Western Europe, and the Asia-Pacific region.
What methods does APT40 use for data exfiltration?+
APT40 uses cloud storage services for data exfiltration.