CNChinaconfidence: 50
APT21APT21
Also known as: HAMMER PANDA · TEMP.Zhenbao · NetTraveler · APT21
Origin
CN
Known aliases
4
Target sectors
2
Attribution
State-sponsored
Profile
APT21 is a Chinese-attributed threat actor catalogued by MISP-Galaxy (MISP-Galaxy v341). The group is also tracked as HAMMER PANDA, TEMP.Zhenbao, NetTraveler. Operational targeting focuses on the Government and Military sectors. Documented victim organisations include Mongolia, Kazakhstan, Tajikistan and 12 other named victims.
Aliases· 4
HAMMER PANDATEMP.ZhenbaoNetTravelerAPT21
Target sectors· 2
GovernmentMilitary
Known victims· 15
- Mongolia
- Kazakhstan
- Tajikistan
- Germany
- United Kingdom
- India
- Kyrgyzstan
- South Korea
- United States
- Chile
- Russia
- China
References
- https://securelist.com/blog/research/35936/nettraveler-is-running-red-star-apt-attacks-compromise-high-profile-victims/
- https://www.cfr.org/interactive/cyber-operations/nettraveler
- https://www.kaspersky.com/about/press-releases/2013_kaspersky-lab-uncovers--operation-nettraveler--a-global-cyberespionage-campaign-targeting-government-affiliated-organizations-and-research-institutes
- https://www.kaspersky.com/about/press-releases/2014_nettraveler-gets-a-makeover-for-10th-anniversary
- https://unit42.paloaltonetworks.com/nettraveler-spear-phishing-email-targets-diplomat-of-uzbekistan/
- https://www.proofpoint.com/us/threat-insight/post/nettraveler-apt-targets-russian-european-interests
- http://www.darkreading.com/endpoint/chinese-cyberspies-pivot-to-russia-in-wake-of-obama-xi-pact/d/d-id/1324242
- https://www.mandiant.com/resources/insights/apt-groups
Related by meaning· 6
Nearest entities by semantic similarity across the cs-graph corpus.