Threat actor · G0065
Leviathan
Also known as MUDCARP, Kryptonite Panda, Gadolinium, BRONZE MOHAWK, TEMP.Jumper, APT40, TEMP.Periscope, Gingham Typhoon.
Leviathan is a Chinese state-sponsored cyber espionage group that has been attributed to the Ministry of State Security's (MSS) Hainan State Security Department and an affiliated front company. Active since at least 2009, Leviathan has targeted the following sectors: academia, aerospace/aviation, biomedical, defense industrial base, government, healthcare, manufacturing, maritime, and transportation across the US, Canada, Australia, Europe, the Middle East, and Southeast Asia.
ATT&CK techniques
50 mappedT1003T1003.001T1021.001T1021.004T1027.001T1027.003T1027.013T1027.015T1041T1047T1055.001T1059.001T1059.005T1074.001T1074.002T1078T1090.003T1102.003T1105T1133T1140T1189T1190T1197T1203T1204.001T1204.002T1218.010T1505.003T1534T1546.003T1547.001T1547.009T1553.002T1559.002T1560T1566.001T1566.002T1567.002T1572T1583.001T1584.004T1584.008T1585.001T1585.002T1586.001T1586.002T1587.004T1589.001T1595.002