Threat group.View on attack.mitre.org
APT1 is a Chinese threat group that has been attributed to the 2nd Bureau of the People’s Liberation Army (PLA) General Staff Department’s (GSD) 3rd Department, commonly known by its Military Unit Cover Designator (MUCD) as Unit 61398.
| Technique | Procedure example |
|---|---|
| T1003.001 LSASS Memory |
APT1 has been known to use credential dumping using Mimikatz. |
| T1005 Data from Local System |
APT1 has collected files from a local victim. |
| T1007 System Service Discovery |
APT1 used the commands |
| T1016 System Network Configuration Discovery |
APT1 used the |
| T1021.001 Remote Desktop Protocol |
The APT1 group is known to have used RDP during operations. |
| T1036.005 Match Legitimate Resource Name or Location |
The file name AcroRD32.exe, a legitimate process name for Adobe's Acrobat Reader, was used by APT1 as a name for malware. |
| T1049 System Network Connections Discovery |
APT1 used the |
| T1057 Process Discovery |
APT1 gathered a list of running processes on the system using |
| T1059.003 Windows Command Shell |
APT1 has used the Windows command shell to execute commands, and batch scripting to automate execution. |
| T1087.001 Local Account |
APT1 used the commands |
| T1114.001 Local Email Collection |
APT1 uses two utilities, GETMAIL and MAPIGET, to steal email. GETMAIL extracts emails from archived Outlook .pst files. |
| T1114.002 Remote Email Collection |
APT1 uses two utilities, GETMAIL and MAPIGET, to steal email. MAPIGET steals email still on Exchange servers that has not yet been archived. |
| T1119 Automated Collection |
APT1 used a batch script to perform a series of discovery techniques and saves it to a text file. |
| T1135 Network Share Discovery |
APT1 listed connected network shares. |
| T1550.002 Pass the Hash |
The APT1 group is known to have used pass the hash. |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.