Loading the current evidence view. Navigation and account controls remain available.
Threat actors
Loading the current evidence view. Navigation and account controls remain available.
Also known as: MUDCARP, Kryptonite Panda, Gadolinium, BRONZE MOHAWK, TEMP.Jumper, APT40, TEMP.Periscope, Gingham Typhoon
50
techniques
17
software
11,671
corpus matches
profile
Leviathan is a Chinese state-sponsored cyber espionage group that has been attributed to the Ministry of State Security's (MSS) Hainan State Security Department and an affiliated front company. Active since at least 2009, Leviathan has targeted the following sectors: academia, aerospace/aviation, biomedical, defense industrial base, government, healthcare, manufacturing, maritime, and transportation across the US, Canada, Australia, Europe, the Middle East, and Southeast Asia.
techniques
50 attributed · most-instrumented first
software
17 malware & tools attributed
Windows Credential Editor
S0005
China Chopper
S0020
Derusbi
S0021
gh0st RAT
S0032
Net
S0039
BLACKCOFFEE
S0069
at
S0110
Cobalt Strike
S0154
Tor
S0183
BITSAdmin
S0190
read this carefully
11,671 corpus matches is not attribution
That count is indicators which exhibit techniques Leviathan is known to use. Many unrelated operators use the same techniques. Treat it as a shared-technique signal for hunting, never as first-party attribution to this group.
indicators exhibiting these techniques
Top by severity: each resolves to its own verdict.
+38 more techniques
PowerSploit
S0194
NanHaiShu
S0228
Orz
S0229
HOMEFRY
S0232
MURKYTOP
S0233
Empire
S0363
BADFLICK
S0642
showing 30 of 11,671
known aliases
Vendors name the same group differently. Searching any alias reaches this profile.