APT
ATLAS
Atlas
Actors
147
Names
508
Sectors
40
Requirements
480
⌘K
▸
sign in
Atlas
Actors
147
Names
508
Sectors
40
Requirements
480
LOADING
Actors
/
Nation-state / APT
/
Asia
Lotus Blossom
G0030
APT
CN · China
AKA
Billbug · Esile · DRAGONFISH · RAFFLES PANDA · Thrip · Red Salamander
CrowdStrike
:
Spring Dragon
Mandiant
:
APT51
Microsoft
:
Raspberry Typhoon
MITRE
:
G0030
Secureworks
:
BRONZE ELGIN
Targets
8
Sectors
9
Threat types
1
GIRs covered
0/480
Active since
2007
Pin to atlas
Watch
Share
Export
Also tracked as
5 vendor names · 6 other aliases
Open Rosetta Stone
CrowdStrike
Spring Dragon
Mandiant
APT51
Microsoft
Raspberry Typhoon
MITRE
G0030
Secureworks
BRONZE ELGIN
UNATTRIBUTED ALIASES
Billbug
Esile
DRAGONFISH
RAFFLES PANDA
Thrip
Red Salamander
Victimology
Geographic footprint · 8 countries
Region filter
Export
origin · China
targeted countries · 8
ASIA ·
7
Hong Kong
·
Indonesia
·
Macau
·
Malaysia
·
Philippines
·
Taiwan
·
Vietnam
AMERICAS ·
1
United States
Sectors targeted
9 of 40
Government
100 actors
Defense
72 actors
Aerospace
59 actors
Technology
60 actors
Telecom
72 actors
Energy / Utilities
59 actors
Education & Research
62 actors
Media & Journalism
49 actors
Industrials / Engineering
29 actors
Tactics, techniques, procedures
Threat types + MITRE ATT&CK mapping
THREAT TYPES
ESP · Espionage
MITRE ATT&CK · 18 techniques
Execution
· 2
T1047
Windows Management Instrumentation
T1059.001
PowerShell
Persistence
· 1
T1543.003
Windows Service
Discovery
· 7
T1012
Query Registry
T1016
System Network Configuration Discovery
Collection
· 2
T1560.001
Archive via Utility
T1560.003
Archive via Custom Method
Exfiltration
· 1
T1048.003
Exfiltration Over Unencrypted Non-C2 Protocol
Command And Control
· 3
T1090.001
Internal Proxy
Defense Impairment
· 1
T1112
Modify Registry
Stealth
· 1
T1134
Access Token Manipulation
GIR coverage
0 / 480 requirements satisfied
Open matrix
No GIRs mapped yet for this actor.
Open data
Machine-readable exports of this profile
JSON · REST
Actor record
Full profile via the public v1 API
STIX 2.1
Intrusion-set bundle
Deterministic ids · techniques + targeted countries
ATT&CK NAVIGATOR
Technique layer
18 techniques · layer format 4.5
Related actors
By origin and actor type
APT31
nation-state
China · 6 targets · since 2013
APT8
nation-state
China · 5 targets · since —
APT2
nation-state
China · 6 targets · since 2010
APT24
nation-state
China · 3 targets · since 2008
APT44
nation-state
Russia · 25 targets · since 2009
APT21
nation-state
China · 5 targets · since 2010
T1018
Remote System Discovery
T1046
Network Service Discovery
T1049
System Network Connections Discovery
T1083
File and Directory Discovery
T1482
Domain Trust Discovery
T1090.003
Multi-hop Proxy
T1219.002
Remote Desktop Software