Loading the current evidence view. Navigation and account controls remain available.
Threat actors
Loading the current evidence view. Navigation and account controls remain available.
Also known as: Comment Crew, Comment Group, Comment Panda
23
techniques
17
software
10,765
corpus matches
profile
APT1 is a Chinese threat group that has been attributed to the 2nd Bureau of the People’s Liberation Army (PLA) General Staff Department’s (GSD) 3rd Department, commonly known by its Military Unit Cover Designator (MUCD) as Unit 61398.
techniques
23 attributed · most-instrumented first
software
17 malware & tools attributed
Mimikatz
S0002
pwdump
S0006
gsecdump
S0008
PoisonIvy
S0012
BISCUIT
S0017
CALENDAR
S0025
GLOOXMAIL
S0026
PsExec
S0029
Net
S0039
Tasklist
S0057
read this carefully
10,765 corpus matches is not attribution
That count is indicators which exhibit techniques APT1 is known to use. Many unrelated operators use the same techniques. Treat it as a shared-technique signal for hunting, never as first-party attribution to this group.
indicators exhibiting these techniques
Top by severity: each resolves to its own verdict.
initial-access
+11 more techniques
ipconfig
S0100
WEBC2
S0109
Cachedump
S0119
Lslsass
S0121
Pass-The-Hash Toolkit
S0122
xCmd
S0123
Seasalt
S0345
showing 30 of 10,765
known aliases
Vendors name the same group differently. Searching any alias reaches this profile.