Threat actor · all actors
APT5G1023 state
🇨🇳 CN
aka APT5, Mulberry Typhoon, MANGANESE, BRONZE FLEETWOOD, Keyhole Panda, UNC2630, TEMP.Bottle, Poisoned Flight, BASALT CASTLE
Last updated: 2026-08-20
About this actor
We have observed one APT group, which we call APT5, particularly focused on telecommunications and technology companies. More than half of the organizations we have observed being targeted or breached by APT5 operate in these sectors. Several times, APT5 has targeted organizations and personnel based in Southeast Asia. APT5 has been active since at least 2007. It appears to be a large threat group that consists of several subgroups, often with distinct tactics and infrastructure. APT5 has targeted or breached organizations across multiple industries, but its focus appears to be on telecommunications and technology companies, especially information about satellite communications. APT5 targeted the network of an electronics firm that sells products for both industrial and military applications. The group subsequently stole communications related to the firm’s business relationship with a national military, including inventories and memoranda about specific products they provided. In one case in late 2014, APT5 breached the network of an international telecommunications company. The group used malware with keylogging capabilities to monitor the computer of an executive who manages the company’s relationships with other telecommunications companies
Source: MITRE ATT&CK
Names & naming systems
Each vendor coins its own name for the same actor. Where a name follows a known scheme we attribute it; the rest are listed honestly as unclassified.
MITRE ATT&CKG-number catalogue id
Microsoftweather-system names
CrowdStrikenation-animal names
Mandiant / genericAPT numbering
MandiantUNC uncategorised cluster
MandiantTEMP temporary cluster
Secureworkscolour-metal names
Unclassifiedno scheme matched
How we know this
- Data origin
- MITRE ATT&CK Imported from the MITRE ATT&CK STIX bundle as an intrusion-set object.
- Techniques
- MITRE ATT&CK STIX mappings — 42 ATT&CK techniques on file.
- Named victims
- None on file.
See how actor data is built for the full pipeline.
Activity timeline
No activity events recorded.
Profile
| CVE | Risk | CVSS | EPSS | Published | Products |
|---|---|---|---|---|---|
| No attributed CVEs. | |||||
T1003OS Credential Dumping ↗T1003.001LSASS Memory ↗T1003.002Security Account Manager ↗T1021Remote Services ↗T1021.001Remote Desktop Protocol ↗T1021.004SSH ↗T1036Masquerading ↗T1036.005Match Legitimate Resource Name or Location ↗T1049System Network Connections Discovery ↗T1053Scheduled Task/Job ↗T1053.003Cron ↗T1055Process Injection ↗T1056Input Capture ↗T1056.001Keylogging ↗T1057Process Discovery ↗T1059Command and Scripting Interpreter ↗T1059.001PowerShell ↗T1059.003Windows Command Shell ↗T1070Indicator Removal ↗T1070.003Clear Command History ↗T1070.004File Deletion ↗T1070.006Timestomp ↗T1074Data Staged ↗T1074.001Local Data Staging ↗T1078Valid Accounts ↗T1078.002Domain Accounts ↗T1078.004Cloud Accounts ↗T1083File and Directory Discovery ↗T1098Account Manipulation ↗T1098.007Additional Local or Domain Groups ↗T1136Create Account ↗T1136.001Local Account ↗T1190Exploit Public-Facing Application ↗T1505Server Software Component ↗T1505.003Web Shell ↗T1554Compromise Host Software Binary ↗T1560Archive Collected Data ↗T1560.001Archive via Utility ↗T1583Acquire Infrastructure ↗T1583.005Botnet ↗T1654Log Enumeration ↗T1685Disable or Modify Tools ↗
Mitigating controls (NIST 800-53)
| Control | Techniques covered | Coverage |
|---|---|---|
SI-4 | 29 / 42 | 69% |
AC-2 | 28 / 42 | 67% |
AC-3 | 28 / 42 | 67% |
AC-6 | 28 / 42 | 67% |
CM-6 | 27 / 42 | 64% |
AC-5 | 24 / 42 | 57% |
CM-5 | 22 / 42 | 52% |
CM-2 | 21 / 42 | 50% |
IA-2 | 21 / 42 | 50% |
CM-7 | 16 / 42 | 38% |
SI-3 | 16 / 42 | 38% |
SI-7 | 14 / 42 | 33% |
RA-5 | 13 / 42 | 31% |
CA-7 | 12 / 42 | 29% |
IA-5 | 11 / 42 | 26% |
Co-occurring actors
None.
Similar actors
Similar TTPs
- C0032 0.37
- Agrius 0.36
- Cutting Edge 0.33
- menuPass 0.32
- FIN13 0.31
Same nation-state
- Night Dragon 1.00
- FunnyDream 1.00
- Operation Wocao 1.00
- C0017 1.00
- Cutting Edge 1.00
Same category
- Night Dragon 1.00
- FunnyDream 1.00
- C0011 1.00
- Operation Wocao 1.00
- Operation Dream Job 1.00