Threat actor · all actors
APT1G0006 state
🇨🇳 CN · PLA · Unit 61398
aka APT1, Comment Crew, Comment Group, Comment Panda, PLA Unit 61398, Byzantine Candor, Group 3, TG-8223, Brown Fox, GIF89a, ShadyRAT, G0006
Last updated: 2026-08-22
About this actor
[APT1](https://attack.mitre.org/groups/G0006) is a Chinese threat group that has been attributed to the 2nd Bureau of the People’s Liberation Army (PLA) General Staff Department’s (GSD) 3rd Department, commonly known by its Military Unit Cover Designator (MUCD) as Unit 61398. (Citation: Mandiant APT1)
Source: MITRE ATT&CK
Names & naming systems
Each vendor coins its own name for the same actor. Where a name follows a known scheme we attribute it; the rest are listed honestly as unclassified.
MITRE ATT&CKG-number catalogue id
CrowdStrikenation-animal names
Mandiant / genericAPT numbering
Unclassifiedno scheme matched
How we know this
- Data origin
- MITRE ATT&CK Imported from the MITRE ATT&CK STIX bundle as an intrusion-set object.
- Techniques
- MITRE ATT&CK STIX mappings — 36 ATT&CK techniques on file.
- Named victims
- None on file.
See how actor data is built for the full pipeline.
Activity timeline
- 2021 — 1 CVE published
- 2017 — 1 CVE published
Profile
| CVE | Risk | CVSS | EPSS | Published | Products |
|---|---|---|---|---|---|
CVE-2017-6328 | 6.9 | 8.8 | 0.0214 | 2017-08-11 | see CVE |
CVE-2020-6789 | 5.8 | 7.8 | 0.0035 | 2021-03-25 | see CVE |
T1003OS Credential Dumping ↗T1003.001LSASS Memory ↗T1005Data from Local System ↗T1007System Service Discovery ↗T1016System Network Configuration Discovery ↗T1021Remote Services ↗T1021.001Remote Desktop Protocol ↗T1036Masquerading ↗T1036.005Match Legitimate Resource Name or Location ↗T1049System Network Connections Discovery ↗T1057Process Discovery ↗T1059Command and Scripting Interpreter ↗T1059.003Windows Command Shell ↗T1087Account Discovery ↗T1087.001Local Account ↗T1114Email Collection ↗T1114.001Local Email Collection ↗T1114.002Remote Email Collection ↗T1119Automated Collection ↗T1135Network Share Discovery ↗T1550Use Alternate Authentication Material ↗T1550.002Pass the Hash ↗T1560Archive Collected Data ↗T1560.001Archive via Utility ↗T1566Phishing ↗T1566.001Spearphishing Attachment ↗T1566.002Spearphishing Link ↗T1583Acquire Infrastructure ↗T1583.001Domains ↗T1584Compromise Infrastructure ↗T1584.001Domains ↗T1585Establish Accounts ↗T1585.002Email Accounts ↗T1588Obtain Capabilities ↗T1588.001Malware ↗T1588.002Tool ↗
Mitigating controls (NIST 800-53)
| Control | Techniques covered | Coverage |
|---|---|---|
SI-4 | 21 / 36 | 58% |
CM-6 | 19 / 36 | 53% |
CM-2 | 16 / 36 | 44% |
AC-3 | 13 / 36 | 36% |
AC-2 | 12 / 36 | 33% |
SI-3 | 12 / 36 | 33% |
AC-6 | 11 / 36 | 31% |
CM-7 | 10 / 36 | 28% |
AC-4 | 9 / 36 | 25% |
IA-2 | 9 / 36 | 25% |
SI-7 | 9 / 36 | 25% |
AC-17 | 8 / 36 | 22% |
CA-7 | 8 / 36 | 22% |
AC-5 | 7 / 36 | 19% |
CM-5 | 7 / 36 | 19% |
Co-occurring actors
- APT41 2 shared CVEs
- APT19 2 shared CVEs
- Winnti Group 2 shared CVEs
- Deep Panda 2 shared CVEs
- Leviathan 2 shared CVEs
- menuPass 2 shared CVEs
- APT3 2 shared CVEs
Similar actors
Similar TTPs
- FunnyDream 0.34
- Ke3chang 0.29
- Aquatic Panda 0.27
- MirrorFace 0.26
- admin@338 0.26
Overlapping CVEs
- Deep Panda 1.00
- APT3 1.00
- Winnti Group 1.00
- menuPass 1.00
- APT41 1.00
Active in same years
- Deep Panda 2.00
- APT3 2.00
- Lazarus Group 2.00
- Winnti Group 2.00
- menuPass 2.00
Same nation-state
- Night Dragon 1.00
- FunnyDream 1.00
- Operation Wocao 1.00
- C0017 1.00
- Cutting Edge 1.00
Same category
- Night Dragon 1.00
- FunnyDream 1.00
- C0011 1.00
- Operation Wocao 1.00
- Operation Dream Job 1.00