APT40: Examining a China-Nexus Espionage Actor « APT40: Examining a China-Nexus Espionage Actor
ID: 6e40ca4e-532b-4e07-a5a1-8cbb94d2b320
STIX ID: report--6e40ca4e-532b-4e07-a5a1-8cbb94d2b320
Threat Score
90/100
Uploaded: 2026-08-14
Published Date: 2019-03-05
Last Modified Date: 2019-03-05
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
FireEye assesses APT40 as a China-nexus, state-sponsored cyber espionage actor active since at least 2013, focused on maritime technology and broader strategic targets tied to the Belt and Road Initiative. The report outlines APT40's mission and attribution, details an attack lifecycle (initial compromise, foothold, privilege escalation, internal reconnaissance, lateral movement, data consolidation/exfiltration), enumerates numerous malware/tools and web shells (e.g., AIRBREAK, PHOTO, CHINA CHOPPER, MURKYTOP, BEACON), and describes infrastructure and behavioral indicators that support moderate-confidence attribution to China and ongoing operational activity.
