APT5 has used the Task Manager process to target LSASS process memory in order to obtain NTLM password hashes. APT5 has also dumped clear text passwords and hashes from memory using Mimikatz hosted through an RDP mapped drive.7
group
APT5 G1023
- Created
- 5 February 2024
- Last modified
- 31 July 2026
- Aliases
- APT5 · Mulberry Typhoon · MANGANESE · BRONZE FLEETWOOD · Keyhole Panda · UNC2630
APT5 is a China-based espionage actor that has been active since at least 2007 primarily targeting the telecommunications, aerospace, and defense industries throughout the U.S., Europe, and Asia. APT5 has displayed advanced tradecraft and significant interest in compromising networking devices and their underlying software including through the use of zero-day exploits.[1][2][3][4][5][6]
Enterprise ATT&CK only. Any Mobile or ICS rows on the same ATT&CK page are not carried.
MITRE reference G1023
APT5 has copied and exfiltrated the SAM Registry hive from targeted systems.8
APT5 has moved laterally throughout victim environments using RDP.9
APT5 has used SSH for lateral movement in compromised environments including for enabling access to ESXi host servers.10
APT5 has named exfiltration archives to mimic Windows Updates at times using filenames with a KB<digits>.zip pattern.11
APT5 has used the BLOODMINE utility to collect data on web requests from Pulse Secure Connect logs.12
Standing G1023
Reach is how much of ATT&CK this group touches. Coverage is how well defended each thing it does is, as a median per technique rather than a total — a total would just restate the reach. Each figure is ranked against all 176 ATT&CK groups only where that population actually spreads. Where most of the population shares one value, a percentile would rank the tie instead of the entity, so the raw value is shown and no rank is claimed.
Reach
65th percentile · 65% of 176 ATT&CK groups have this many Enterprise techniques or fewer.
66th percentile · 66% of 176 ATT&CK groups have this many tactics spanned or fewer.
86th percentile · 86% of 176 ATT&CK groups have this many tools and malware or fewer.
89% of the population shares a single value across only 4 distinct values, so a percentile here would rank the tie, not the entity.
Coverage
73rd percentile · 73% of 176 ATT&CK groups have this many detection rules per technique or fewer.
Detection coverage G1023
1429 distinct rules cover the 29 techniques recorded for this group. The 1531 technique-to-rule mappings resolve to 1429 distinct rules, because one rule can cover several techniques. 940 Sigma · 489 Splunk.
Loading detections...
| Select | Title | Description | Category | Status | Event | Product | MITRE ATT&CK | CVEs | Severity | Author | Created | Updated | ID | Refs |
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
© 2026 The MITRE Corporation. ATT&CK® and D3FEND™ data reproduced with permission. SigmaHQ detection rules licensed under DRL 1.1. attack.mitre.org · d3fend.mitre.org · CAR analytics licensed under Apache 2.0 · car.mitre.org