THREAT_ACTOR · G0006
APT1
Also known as: APT1, Comment Crew, Comment Group, Comment Panda
Profile
APT1 is a Chinese threat group that has been attributed to the 2nd Bureau of the People’s Liberation Army (PLA) General Staff Department’s (GSD) 3rd Department, commonly known by its Military Unit Cover Designator (MUCD) as Unit 61398.
MITRE ATT&CK ↗Techniques
23 ATT&CK techniques attributed to this actor.
T1003.001 LSASS MemoryT1005 Data from Local SystemT1007 System Service DiscoveryT1016 System Network Configuration DiscoveryT1021.001 Remote Desktop ProtocolT1036.005 Match Legitimate Resource Name or LocationT1049 System Network Connections DiscoveryT1057 Process DiscoveryT1059.003 Windows Command ShellT1087.001 Local AccountT1114.001 Local Email CollectionT1114.002 Remote Email CollectionT1119 Automated CollectionT1135 Network Share DiscoveryT1550.002 Pass the HashT1560.001 Archive via UtilityT1566.001 Spearphishing AttachmentT1566.002 Spearphishing LinkT1583.001 DomainsT1584.001 DomainsT1585.002 Email AccountsT1588.001 MalwareT1588.002 Tool
Software
17 malware/tools attributed to this actor.
MimikatzpwdumpgsecdumpPoisonIvyBISCUITCALENDARGLOOXMAILPsExecNetTasklistipconfigWEBC2CachedumpLslsassPass-The-Hash ToolkitxCmdSeasalt
Related corpus activity
9,573 indicators EXHIBIT techniques this actor uses. This is a shared-technique signal, not a first-party attribution to APT1.
| Indicator | Type | Family | Sev | Src |
|---|---|---|---|---|
| cve-2023-44976 | cve | ransomware | 85 | 2 |
| cve-2026-0740 | cve | — | 85 | 1 |
| cve-2025-11837 | cve | — | 85 | 2 |
| cve-2026-3102 | cve | — | 85 | 3 |
| cve-2025-34117 | cve | — | 85 | 1 |
| cve-2026-1969 | cve | — | 85 | 1 |
| cve-2025-0921 | cve | — | 85 | 2 |
| cve-2013-3307 | cve | — | 85 | 2 |
| cve-2025-34054 | cve | — | 85 | 4 |
| cve-2014-2321 | cve | — | 85 | 1 |
| cve-2020-17456 | cve | — | 85 | 1 |
| cve-2025-2492 | cve | — | 85 | 2 |
| cve-2013-7471 | cve | — | 85 | 1 |
| cve-2021-29441 | cve | — | 85 | 1 |
| cve-2025-23304 | cve | — | 85 | 2 |
| cve-2025-66478 | cve | — | 85 | 2 |
| cve-2026-22584 | cve | — | 85 | 2 |
| cve-2021-27076 | cve | — | 85 | 1 |
| cve-2025-68670 | cve | — | 85 | 2 |
| cve-2016-15047 | cve | — | 85 | 4 |
| cve-2024-1781 | cve | — | 85 | 1 |
| cve-2018-8007 | cve | — | 85 | 1 |
| cve-2016-5681 | cve | — | 85 | 2 |
| cve-2021-4045 | cve | — | 85 | 1 |
| cve-2020-22653 | cve | — | 85 | 2 |
| cve-2020-22658 | cve | — | 85 | 2 |
| cve-2026-4368 | cve | ransomware | 85 | 1 |
| cve-2017-18377 | cve | — | 85 | 1 |
| cve-2021-25646 | cve | — | 85 | 1 |
| cve-2026-3844 | cve | — | 85 | 1 |
Showing the top 30 by severity of 9,573.