logo

APT1__2013__Mandiant_APT1_Report.pdf

ID: 53bc8857-9a94-4f60-a04c-0108f2730f72

STIX ID: report--53bc8857-9a94-4f60-a04c-0108f2730f72

Threat Score

92/100

Uploaded: 2026-08-07

Published Date: 2013-02-18

Last Modified Date: 2013-02-18

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
This Mandiant report exposes and attributes the activities of APT1 (linked to PLA Unit 61398), documenting a persistent, organized Chinese cyber-espionage campaign active since at least 2006 that compromised at least 141 organizations across ~20 industries, stole hundreds of terabytes of intellectual property, used a large global command-and-control and hop infrastructure (centred on Shanghai), developed and operated numerous custom malware families and utilities (e.g., WEBC2, GETMAIL, MAPIGET), and includes operator personas, infrastructure mappings, and over 3,000 Indicators of Compromise to aid detection and remediation.