APT
ATLAS
Atlas
Actors
147
Names
508
Sectors
40
Requirements
480
⌘K
▸
sign in
Atlas
Actors
147
Names
508
Sectors
40
Requirements
480
LOADING
APT5 (aka UNC2630, Mulberry Typhoon) · APT Atlas
Actors
/
Nation-state / APT
/
Asia
APT5
G0021
APT
CN · China
AKA
UNC2630 · Mulberry Typhoon · Poisoned Flight
Microsoft
:
MANGANESE
CrowdStrike
:
KEYHOLE PANDA
Secureworks
:
BRONZE FLEETWOOD
MITRE
:
G0021
Targets
15
Sectors
6
Threat types
1
GIRs covered
0/480
Active since
2007
Pin to atlas
Watch
Share
Export
Also tracked as
5 vendor names · 3 other aliases
Open Rosetta Stone
CrowdStrike
KEYHOLE PANDA
Mandiant
APT5
Microsoft
MANGANESE
MITRE
G0021
Secureworks
BRONZE FLEETWOOD
UNATTRIBUTED ALIASES
UNC2630
Mulberry Typhoon
Poisoned Flight
Victimology
Geographic footprint · 15 countries
Region filter
Export
origin · China
targeted countries · 15
OCEANIA ·
1
Australia
EUROPE ·
9
Belgium
·
Switzerland
·
Germany
·
France
·
United Kingdom
·
Ireland
·
Italy
·
Norway
·
Sweden
AMERICAS ·
2
Canada
·
United States
ASIA ·
3
Japan
·
South Korea
·
Taiwan
Sectors targeted
6 of 40
Government
100 actors
Defense
72 actors
Aerospace
59 actors
Technology
60 actors
Telecom
72 actors
Dissidents (as targets)
16 actors
Tactics, techniques, procedures
Threat types + MITRE ATT&CK mapping
THREAT TYPES
ESP · Espionage
MITRE ATT&CK · 22 techniques
Resource Development
· 1
T1583.005
Botnet
Initial Access
· 1
T1190
Exploit Public-Facing Application
Execution
· 3
T1053.003
Cron
T1059.001
PowerShell
Persistence
· 1
T1554
Compromise Host Software Binary
Credential Access
· 2
T1003.001
LSASS Memory
Discovery
· 4
T1049
System Network Connections Discovery
Lateral Movement
· 2
T1021.001
Remote Desktop Protocol
T1021.004
SSH
Collection
· 1
T1560.001
Archive via Utility
Defense Impairment
· 1
T1685
Disable or Modify Tools
Stealth
· 6
T1036.005
Match Legitimate Resource Name or Location
T1055
Process Injection
GIR coverage
0 / 480 requirements satisfied
Open matrix
No GIRs mapped yet for this actor.
Open data
Machine-readable exports of this profile
JSON · REST
Actor record
Full profile via the public v1 API
STIX 2.1
Intrusion-set bundle
Deterministic ids · techniques + targeted countries
ATT&CK NAVIGATOR
Technique layer
22 techniques · layer format 4.5
Related actors
By origin and actor type
APT31
nation-state
China · 6 targets · since 2013
APT8
nation-state
China · 5 targets · since —
APT2
nation-state
China · 6 targets · since 2010
APT24
nation-state
China · 3 targets · since 2008
APT44
nation-state
Russia · 25 targets · since 2009
APT21
nation-state
China · 5 targets · since 2010
T1059.003
Windows Command Shell
T1003.002
Security Account Manager
T1057
Process Discovery
T1083
File and Directory Discovery
T1654
Log Enumeration
T1070
Indicator Removal
T1070.004
File Deletion
T1078.002
Domain Accounts
T1078.004
Cloud Accounts