Threat actor · all actors
admin@338G0018 state
🇨🇳 CN
aka admin@338, TEMPER PANDA, Admin338, Team338, MAGNESIUM, G0018
Last updated: 2026-08-20
About this actor
[admin@338](https://attack.mitre.org/groups/G0018) is a China-based cyber threat group. It has previously used newsworthy events as lures to deliver malware and has primarily targeted organizations involved in financial, economic, and trade policy, typically using publicly available RATs such as [PoisonIvy](https://attack.mitre.org/software/S0012), as well as some non-public backdoors. (Citation: FireEye admin@338)
Source: MITRE ATT&CK
Names & naming systems
Each vendor coins its own name for the same actor. Where a name follows a known scheme we attribute it; the rest are listed honestly as unclassified.
MITRE ATT&CKG-number catalogue id
CrowdStrikenation-animal names
Unclassifiedno scheme matched
How we know this
- Data origin
- MITRE ATT&CK Imported from the MITRE ATT&CK STIX bundle as an intrusion-set object.
- Techniques
- MITRE ATT&CK STIX mappings — 18 ATT&CK techniques on file.
- Named victims
- None on file.
See how actor data is built for the full pipeline.
Activity timeline
No activity events recorded.
Profile
| CVE | Risk | CVSS | EPSS | Published | Products |
|---|---|---|---|---|---|
| No attributed CVEs. | |||||
T1007System Service Discovery ↗T1016System Network Configuration Discovery ↗T1036Masquerading ↗T1036.005Match Legitimate Resource Name or Location ↗T1049System Network Connections Discovery ↗T1059Command and Scripting Interpreter ↗T1059.003Windows Command Shell ↗T1069Permission Groups Discovery ↗T1069.001Local Groups ↗T1082System Information Discovery ↗T1083File and Directory Discovery ↗T1087Account Discovery ↗T1087.001Local Account ↗T1203Exploitation for Client Execution ↗T1204User Execution ↗T1204.002Malicious File ↗T1566Phishing ↗T1566.001Spearphishing Attachment ↗
Mitigating controls (NIST 800-53)
| Control | Techniques covered | Coverage |
|---|---|---|
SI-4 | 11 / 18 | 61% |
CM-6 | 10 / 18 | 56% |
SI-3 | 9 / 18 | 50% |
CA-7 | 8 / 18 | 44% |
CM-2 | 8 / 18 | 44% |
CM-7 | 7 / 18 | 39% |
SI-7 | 7 / 18 | 39% |
SI-10 | 6 / 18 | 33% |
AC-2 | 5 / 18 | 28% |
AC-4 | 5 / 18 | 28% |
AC-6 | 5 / 18 | 28% |
IA-9 | 5 / 18 | 28% |
SC-44 | 5 / 18 | 28% |
SC-7 | 5 / 18 | 28% |
SI-2 | 5 / 18 | 28% |
Co-occurring actors
None.
Similar actors
Similar TTPs
- Poseidon Group 0.32
- Nomadic Octopus 0.32
- Darkhotel 0.30
- TA459 0.30
- Machete 0.30
Same nation-state
- Night Dragon 1.00
- FunnyDream 1.00
- Operation Wocao 1.00
- C0017 1.00
- Cutting Edge 1.00
Same category
- Night Dragon 1.00
- FunnyDream 1.00
- C0011 1.00
- Operation Wocao 1.00
- Operation Dream Job 1.00