THREAT_ACTOR · G0018
admin@338
Also known as: admin@338
Profile
admin@338 is a China-based cyber threat group. It has previously used newsworthy events as lures to deliver malware and has primarily targeted organizations involved in financial, economic, and trade policy, typically using publicly available RATs such as PoisonIvy, as well as some non-public backdoors.
MITRE ATT&CK ↗Techniques
12 ATT&CK techniques attributed to this actor.
T1007 System Service DiscoveryT1016 System Network Configuration DiscoveryT1036.005 Match Legitimate Resource Name or LocationT1049 System Network Connections DiscoveryT1059.003 Windows Command ShellT1069.001 Local GroupsT1082 System Information DiscoveryT1083 File and Directory DiscoveryT1087.001 Local AccountT1203 Exploitation for Client ExecutionT1204.002 Malicious FileT1566.001 Spearphishing Attachment
Software
7 malware/tools attributed to this actor.
PoisonIvyNetLOWBALLBUBBLEWRAPSysteminfoipconfignetstat
Related corpus activity
9,545 indicators EXHIBIT techniques this actor uses. This is a shared-technique signal, not a first-party attribution to admin@338.
| Indicator | Type | Family | Sev | Src |
|---|---|---|---|---|
| cve-2021-4045 | cve | — | 85 | 1 |
| cve-2026-1969 | cve | — | 85 | 1 |
| cve-2025-68670 | cve | — | 85 | 2 |
| cve-2023-44976 | cve | ransomware | 85 | 2 |
| cve-2026-4368 | cve | ransomware | 85 | 1 |
| cve-2021-29441 | cve | — | 85 | 1 |
| cve-2026-22584 | cve | — | 85 | 2 |
| cve-2025-11837 | cve | — | 85 | 2 |
| cve-2024-1781 | cve | — | 85 | 1 |
| cve-2026-3102 | cve | — | 85 | 3 |
| cve-2020-22658 | cve | — | 85 | 2 |
| cve-2025-34117 | cve | — | 85 | 1 |
| cve-2021-25646 | cve | — | 85 | 1 |
| cve-2025-23304 | cve | — | 85 | 2 |
| cve-2025-66478 | cve | — | 85 | 2 |
| cve-2025-0921 | cve | — | 85 | 2 |
| cve-2021-27076 | cve | — | 85 | 1 |
| cve-2013-3307 | cve | — | 85 | 2 |
| cve-2016-15047 | cve | — | 85 | 4 |
| cve-2025-34054 | cve | — | 85 | 4 |
| cve-2018-8007 | cve | — | 85 | 1 |
| cve-2014-2321 | cve | — | 85 | 1 |
| cve-2020-17456 | cve | — | 85 | 1 |
| cve-2020-22653 | cve | — | 85 | 2 |
| cve-2016-5681 | cve | — | 85 | 2 |
| cve-2025-2492 | cve | — | 85 | 2 |
| cve-2017-18377 | cve | — | 85 | 1 |
| cve-2013-7471 | cve | — | 85 | 1 |
| cve-2022-47945 | cve | — | 85 | 1 |
| cve-2026-0740 | cve | — | 85 | 1 |
Showing the top 30 by severity of 9,545.