CyberzSOC

Publication detail
← Back to advisories & guidance

People’s Republic of China (PRC) Ministry of State Security APT40 Tradecraft in Action ↗ source

July 8, 2024 NSA Advisory
Co-sealed by: ASD/ACSC, BND, CCCS, CISA, FBI, NCSC-NZ, NCSC-UK, NIS, NISC, NPA, NSA

Summary

The advisory draws on the authoring agencies’ shared understanding of the threat as well as ASD’s ACSC incident response investigations. The PRC state-sponsored cyber group has previously targeted organizations in various countries, including Australia and the United States, and the techniques highlighted below are regularly used by other PRC state-sponsored actors globally. Therefore, the authoring agencies believe the group, and similar techniques remain a threat to their countries’ networks as well. The authoring agencies assess that this group conduct malicious cyber operations for the PRC Ministry of State Security (MSS). The activity and techniques overlap with the groups tracked as Advanced Persistent Threat (APT) 40 (also known as Kryptonite Panda, GINGHAM TYPHOON, Leviathan and Bronze Mohawk in industry reporting). This group has previously been reported as being based in Haikou, Hainan Province, PRC and receiving tasking from the PRC MSS, Hainan State Security Department.[1] The following Advisory provides a sample of significant case studies of this adversary’s techniques in action against two victim networks.

News Coverage

No coverage found in monitored research blogs or news feeds.

CVEs Referenced in This Publication

CVECVSSAffected
CVE-2021-44228 10.0 Critical Apache Log4j2 Apache Log4j2 contains a vulnerability where JNDI features do not protect against attacker-controlled JNDI-related endpoints, allowing for remote cod…
CVE-2021-26084 9.8 Critical Atlassian Confluence Server and Data Center Atlassian Confluence Server and Data Server contain an Object-Graph Navigation Language (OGNL) injection vulnerability that may allow an unauthentica…
CVE-2021-34473 9.1 Critical Microsoft Exchange Server Microsoft Exchange Server contains an unspecified vulnerability that allows for remote code execution.
CVE-2021-34523 9.0 Critical Microsoft Exchange Server Microsoft Exchange Server contains an unspecified vulnerability that allows for privilege escalation.
CVE-2021-31207 6.6 Medium Microsoft Exchange Server Microsoft Exchange Server contains an unspecified vulnerability that allows for security feature bypass.

Extracted from the publication text. Each CVE links to its tracked detail page.

Vendors Named in This Publication

Each vendor links to its Known Exploited Vulnerabilities catalog page. Only vendors that appear in the KEV catalog are listed, either because the publication cites one of their KEV entries or because it names them directly.