APT1__2013__Mandiant_APT1_Report.pdf
ID: 53bc8857-9a94-4f60-a04c-0108f2730f72
STIX ID: report--53bc8857-9a94-4f60-a04c-0108f2730f72
Threat Score
92/100
Uploaded: 2026-08-07
Published Date: 2013-02-18
Last Modified Date: 2013-02-18
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
This Mandiant report exposes and attributes the activities of APT1 (linked to PLA Unit 61398), documenting a persistent, organized Chinese cyber-espionage campaign active since at least 2006 that compromised at least 141 organizations across ~20 industries, stole hundreds of terabytes of intellectual property, used a large global command-and-control and hop infrastructure (centred on Shanghai), developed and operated numerous custom malware families and utilities (e.g., WEBC2, GETMAIL, MAPIGET), and includes operator personas, infrastructure mappings, and over 3,000 Indicators of Compromise to aid detection and remediation.
