Leviathan
APT40 is a China-attributed threat actor also tracked as Leviathan, Bronze Mohawk, Feverdream, Gadolinium, Gingham Typhoon, JJDoor, Kryptonite Panda, Mudcarp, Red Ladon, TEMP.Jumper, and TEMP.Periscope. The content describes the group conducting operations against port authorities and maritime communication networks in Malaysia and other ASEAN members between 2017 and 2019. It also states that the group conducted reconnaissance against target networks to identify vulnerable, end-of-life, or no longer maintained devices for rapid exploitation. Observed tradecraft in the provided content includes spearphishing emails with malicious attachments such as .rtf, .doc, and .xls files; user-execution lures via spearphishing attachments; use of PowerShell and WMI for execution; Base64 obfuscation; JavaScript that creates a shortcut file in the Startup folder pointing to the main backdoor; use of a DLL known as SeDll to decrypt and execute other JavaScript backdoors; staging data remotely prior to exfiltration; exfiltration over command-and-control channels; use of compromised legitimate websites as command-and-control nodes; use of multi-hop proxies to disguise malicious traffic; use of staging directories including C:\Windows\Debug and C:\Perflogs; storage of captured credential material in local log files on victim systems during Leviathan Australian intrusions; targeting of RDP credentials and use of those credentials to move through victim environments; and use of an uploader known as LUNCHMONEY to exfiltrate files to Dropbox. The content also states that APT40 activity in the South China Sea region foreshadowed later China-linked focus on ports and maritime logistics.
Know when an actor pivots toward your sector
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Targeting
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Where they target
Geographies tied to known operations.
- 🇦🇺 Australia
Tradecraft
52 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
Associated malware families
33 malware families attributed to this actor across reporting.
28 additional families tracked in Mallory.
Associated vulnerabilities
13 CVEs this actor has used in observed campaigns. 13 of them exploited in the wild.
...used exploits for... Word (CVE-2017-0199)...
APT40 leverages exploits in their phishing operations, often weaponizing vulnerabilities within days of their disclosure. Observed vulnerabilities include: CVE-2012-0158 CVE-2017-0199 CVE-2017-8759 CVE-2017-11882
APT40 leverages exploits in their phishing operations, often weaponizing vulnerabilities within days of their disclosure. Observed vulnerabilities include: CVE-2012-0158 CVE-2017-0199 CVE-2017-8759 CVE-2017-11882
This detection identifies instances where Windows Explorer.exe spawns PowerShell or cmd.exe processes, particularly focusing on executions initiated by LNK files. This behavior is associated with the ZDI-CAN-25373 Windows shortcut zero-day vulnerability, where specially crafted LNK files are used to trigger malicious code execution through cmd.exe or powershell.exe. This technique has been actively exploited by multiple APT groups in targeted attacks through both HTTP and SMB delivery methods.
APT40 leverages exploits in their phishing operations, often weaponizing vulnerabilities within days of their disclosure. Observed vulnerabilities include: CVE-2012-0158 CVE-2017-0199 CVE-2017-8759 CVE-2017-11882
8 more CVEs tied to this actor tracked in Mallory.
Observables
118 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
Recent activity
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Named threat actor referenced in global threat reporting.
Listed as a threat actor associated with the PowerShell P/Invoke process injection API chain detection and related ATT&CK techniques.
Listed as a threat actor associated with PowerShell execution behavior relevant to this detection analytic.
Listed as a threat actor associated with use of Cobalt Strike PowerShell loader patterns.
The version that knows your environment.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.