logo

APT40: Examining a China-Nexus Espionage Actor « APT40: Examining a China-Nexus Espionage Actor

ID: 6e40ca4e-532b-4e07-a5a1-8cbb94d2b320

STIX ID: report--6e40ca4e-532b-4e07-a5a1-8cbb94d2b320

Threat Score

90/100

Uploaded: 2026-08-14

Published Date: 2019-03-05

Last Modified Date: 2019-03-05

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
FireEye assesses APT40 as a China-nexus, state-sponsored cyber espionage actor active since at least 2013, focused on maritime technology and broader strategic targets tied to the Belt and Road Initiative. The report outlines APT40's mission and attribution, details an attack lifecycle (initial compromise, foothold, privilege escalation, internal reconnaissance, lateral movement, data consolidation/exfiltration), enumerates numerous malware/tools and web shells (e.g., AIRBREAK, PHOTO, CHINA CHOPPER, MURKYTOP, BEACON), and describes infrastructure and behavioral indicators that support moderate-confidence attribution to China and ongoing operational activity.