TLP:CLEAR
⚠ NATION-STATE · PLA GENERAL STAFF DEPT, 3RD DEPT, 2ND BUREAU (UNIT 61398) · CHINA
// Threat Actor Profile — Military Cyber Espionage Unit / Intellectual-Property Theft (Historical)

APT1

PROFILE COMPILED: 2026-08-29  |  SOURCES: Mandiant "APT1: Exposing One of China's Cyber Espionage Units" (2013), MITRE ATT&CK (G0006), U.S. DOJ, FBI, CFR Cyber Operations Tracker, Lawfare, SecurityWeek, Wikipedia, 10+ additional vendor/press sources
Status: DORMANT / LIKELY ABSORBED INTO RESTRUCTURED PLA CYBER UNITS SINCE 2015–16
Threat Level: HIGH (Historical)
Primary Motive: State-Directed Economic & Political Espionage
Active Since: At least 2006 (per Mandiant forensic evidence)
MITRE ATT&CK: G0006
141+
Organizations Compromised Across 20+ Strategic Industries, 2006–2013+
356 Days
Average Dwell Time — Longest Documented Intrusion: 1,764 Days (~4.8 Years)
937
Identified C2 Servers Across 13 Countries Supporting 40+ Custom Tools
2014
Year DOJ Indicted 5 Named PLA Officers — First-Ever US State-Actor Indictment
00
Overview

In February 2013, Mandiant published "APT1: Exposing One of China's Cyber Espionage Units," a report that did something no commercial security company had done before at that scale: it named a specific unit of a specific country's military — the People's Liberation Army's Unit 61398 — attributed a multi-year cyber-espionage campaign to a specific 12-story building in Shanghai's Pudong New Area, and published network infrastructure, photographs, and even named individual operators. The group Mandiant called APT1 (also tracked as Comment Crew, Comment Group, and Comment Panda) had, since at least 2006, systematically compromised at least 141 organizations across 20 major industries, stealing hundreds of terabytes of intellectual property.

APT1 is widely regarded as the single most consequential public attribution in the history of commercial cyber threat intelligence. Rather than relying on novel malware, APT1 achieved its scale and persistence primarily through fluent, well-crafted spear-phishing and a large but largely homegrown malware ecosystem (WEBC2 backdoors, BISCUIT, and dozens of other custom tools), maintained through more than 937 identified command-and-control servers across 13 countries. Average dwell time inside a victim network was 356 days; the longest documented single intrusion lasted 1,764 days — nearly five years.

The report's impact extended well beyond APT1 itself. It is widely credited with helping create the modern commercial cyber threat intelligence industry, establishing the "APTn" naming convention still used across the field today, and directly shaping U.S. government policy: in May 2014 the Department of Justice indicted five named PLA officers — the first criminal indictment of state-sponsored hackers by any government — and the group's exposure is assessed by analysts as one contributing factor in China's 2015 PLA restructuring, which folded military cyber capability into the newly created Strategic Support Force.

APT1 today is best treated as a historical case file rather than an active tracked threat: public reporting and Mandiant's own follow-on observations describe the group rapidly curtailing operations and shutting down exposed infrastructure within weeks of the 2013 report's release. Its lasting relevance is doctrinal and historical — as the first large-scale, publicly documented demonstration that a nation-state's economic-espionage apparatus could be identified, named, and disrupted through open-source and forensic investigation by a private company, and as the direct ancestor of nearly every public nation-state attribution report published since.

01
Identity & Attribution
Primary NameAPT1
Sponsor / ParentPeople's Liberation Army (PLA), General Staff Department, 3rd Department, 2nd Bureau — Military Unit Cover Designator (MUCD) "Unit 61398" (pre-2015 restructuring designation)
Actor TypeNation-State — Military Cyber Espionage Unit
Primary MotivationState-directed economic espionage (intellectual property theft); secondarily political/state-secret collection
Active SinceAt least 2006 (per Mandiant's forensic evidence); some indicators suggest earlier origins
Last ObservedOperations sharply curtailed after February 2013 exposure; no significant activity publicly attributed to this designation since the PLA's 2015–16 Strategic Support Force restructuring
MITRE G-IDG0006
Legal StatusFive named PLA officers (Wang Dong "UglyGorilla," Sun Kailiang, Wen Xinyu, Huang Zhenyu, Gu Chunhui) indicted by US DOJ, May 2014, on 31 counts; FBI issued public wanted posters; no arrests or extraditions to date absent a US–China extradition treaty
Tracking Aliases
APT1 Comment Crew Comment Group Comment Panda PLA Unit 61398
Attribution Confidence

Attribution is HIGH — among the highest-confidence nation-state attributions ever published. Mandiant's 2013 report combined operational-security failures by individual operators (reused personas, registration email addresses, and forum handles) with physical infrastructure evidence (IP address blocks routed through the same telecommunications infrastructure serving the Unit 61398 facility) and was subsequently corroborated by the US Department of Justice's independent investigation, which resulted in a formal criminal indictment naming specific individuals in May 2014 — a level of corroboration (private-sector forensic attribution followed by independent government indictment) rarely achieved for nation-state cyber activity before or since.

02
Campaign & Operational Timeline
2006
Earliest Observed Activity
Mandiant's forensic timeline places the earliest confirmed APT1 intrusions in 2006, though some registered infrastructure and operator personas suggest the group or its precursor elements may have been active earlier.
2006 –
2010
Establishing Scale — Custom Malware & C2 Infrastructure
Builds a large, largely homegrown malware ecosystem (WEBC2-family backdoors, BISCUIT, and dozens of other custom tools) and registers hundreds of domains supporting more than 937 identified command-and-control servers across 13 countries.
2010 –
2013
Peak Operational Tempo
Compromises the majority of its documented 141+ victim organizations during this window, systematically targeting 20 industries identified as strategic in China's 12th Five-Year Plan, with aerospace and IT firms as leading targets; individual intrusions average 356 days of dwell time, with the longest lasting 1,764 days.
FEB 2013
Mandiant "APT1" Report Publication
Mandiant publishes its 74-page report publicly attributing the group to PLA Unit 61398, naming the Shanghai facility, publishing IP infrastructure, and identifying individual operator personas (UglyGorilla, SuperHard, DOTA). The group rapidly shuts down exposed C2 infrastructure and curtails operations within weeks.
MAY 2014
US DOJ Indictment
Department of Justice unseals a 31-count indictment against five named PLA officers (Wang Dong, Sun Kailiang, Wen Xinyu, Huang Zhenyu, Gu Chunhui) — the first criminal indictment of state-sponsored hackers by any national government. FBI issues public wanted posters.
2015 –
2016
PLA Restructuring & Apparent Dissolution of the Unit 61398 Cyber Function
China undertakes sweeping PLA reforms creating the Strategic Support Force, consolidating military cyber, space, and electronic-warfare capability. Activity linked to APT1/Unit 61398's specific infrastructure and toolset does not resurface under this designation; analysts assess personnel and capability were likely absorbed into restructured PLA cyber units.
03
Attack Lifecycle Scale and persistence, not technical novelty

APT1's operational model favored breadth and persistence over technical sophistication. Initial access relied overwhelmingly on spear-phishing — emails crafted in fluent, idiomatic English, tailored to a specific recipient's role, carrying malicious attachments or links designed to trigger backdoor installation (T1566.001, T1566.002). The group registered hundreds of its own domains and periodically hijacked legitimate FQDNs to serve as staging and command infrastructure, giving it enormous operational depth and the ability to rotate infrastructure faster than defenders of the era could blocklist it.

Once inside a victim environment, APT1 relied on a mix of custom-built backdoors — most notably the WEBC2 family, which retrieved attacker commands embedded in ordinary-looking web pages, and BISCUIT, used from as early as 2007 — alongside publicly available tools like Poison Ivy and Gh0st RAT when convenient. Credential theft leaned on tools such as Mimikatz for in-memory credential extraction and pass-the-hash techniques for lateral movement, while native Windows utilities (net, tasklist, ipconfig) handled the bulk of internal reconnaissance, minimizing the group's custom-tooling footprint during discovery and blending into normal administrative activity.

Data collection and exfiltration were methodical and large-scale: purpose-built tools like GETMAIL (targeting local Outlook .pst files) and MAPIGET (targeting Exchange servers directly) allowed bulk email harvesting, and collected data was typically compressed with RAR before exfiltration. The group's defining operational characteristic was not stealth in the sense of avoiding all detection, but persistence — average dwell times measured in the better part of a year gave operators time to methodically map an organization's file shares, identify high-value intellectual property, and exfiltrate it repeatedly over months, in several documented cases returning to the same victim organization across multiple, non-contiguous intrusion windows.

04
TTPs — MITRE ATT&CK Mapping Enterprise framework; mapped against G0006
Resource Development
T1583.001
Acquire Infrastructure: Domains
[HIGH] Registered hundreds of domains supporting a large, redundant C2 footprint of 937+ identified servers across 13 countries.
Resource Development
T1584.001
Compromise Infrastructure: Domains
[MEDIUM] Hijacked FQDNs belonging to legitimate, unrelated websites to serve as covert staging and hop points.
Initial Access
T1566.001
Phishing: Spearphishing Attachment
[HIGH] Sent fluent, role-tailored spear-phishing emails with malicious attachments as the group's primary initial-access vector.
Initial Access
T1566.002
Phishing: Spearphishing Link
[HIGH] Used malicious hyperlinks embedded in phishing emails as an alternate initial-access method.
Defense Evasion
T1036.005
Masquerading: Match Legitimate Name or Location
[MEDIUM] Named malware payloads (e.g., AcroRD32.exe) to mimic legitimate software such as Adobe Acrobat Reader.
Credential Access
T1003.001
OS Credential Dumping: LSASS Memory
[HIGH] Used Mimikatz to extract credentials from LSASS memory to support lateral movement.
Lateral Movement
T1550.002
Use Alternate Authentication Material: Pass the Hash
[HIGH] Employed pass-the-hash techniques to move laterally without needing plaintext credentials.
Lateral Movement
T1021.001
Remote Services: Remote Desktop Protocol
[MEDIUM] Used RDP to move between compromised hosts within victim networks.
Discovery
T1087.001
Account Discovery: Local Account
[MEDIUM] Used native commands (net localgroup, net user, net group) for account enumeration to blend with normal admin activity.
Discovery
T1135
Network Share Discovery
[MEDIUM] Enumerated connected network shares to locate valuable file repositories and intellectual property.
Collection
T1114
Email Collection
[HIGH] Used custom tools GETMAIL (Outlook .pst extraction) and MAPIGET (direct Exchange server theft) for bulk email harvesting.
Collection / Exfiltration Prep
T1560.001
Archive Collected Data: Archive via Utility
[HIGH] Compressed staged data with RAR utilities prior to exfiltration to reduce transfer footprint.
05
Targeting Profile
Sector Targeting
Information Technology
PRIMARY
Aerospace & Satellite (15+ known victims)
HIGH
Telecommunications (10+ intrusions)
MED
Energy, Engineering & Manufacturing
MED
Public Administration & International Orgs
LOW
GeographiesOverwhelmingly United States-based victims (including all entities named in the 2014 indictment); also observed against organizations in Canada, the UK, and other industrialized economies
Victim ProfileLarge enterprises and government-adjacent organizations holding high-value intellectual property, trade secrets, or engineering data; frequent repeat targeting of the same organizations across multiple, non-contiguous intrusion windows
Preferred EntryFluent, role-tailored spear-phishing (attachments and links) as the near-universal initial-access vector; minimal reliance on exploit-based initial access relative to contemporaries
Target DoctrineSystematic harvesting aligned to explicit Chinese industrial-policy priorities (the 12th Five-Year Plan's seven strategic emerging industries) rather than opportunistic or purely military targeting — one of the clearest documented examples of cyber-espionage directly in service of stated economic-development goals
06
Tools, Malware & Infrastructure
WEBC2 Backdoor Family Custom Backdoor · APT1-Developed
The tool family that gave rise to the "Comment Crew" nickname: retrieves a web page from an attacker-controlled C2 server and interprets attacker commands embedded within specially formatted HTML comments/tags — a design that let C2 traffic resemble ordinary web browsing to network defenders of the era.
BISCUIT Custom Backdoor · APT1-Developed
One of APT1's longest-running custom backdoors, in use since at least 2007; provided persistent remote access and was one of dozens of bespoke tools within the group's roughly 40-tool custom malware arsenal.
GETMAIL / MAPIGET Custom Data-Theft Utilities
Purpose-built tools for bulk email theft: GETMAIL extracted local Outlook .pst archive files, while MAPIGET queried Exchange servers directly — reflecting the group's systematic, industrial-scale approach to harvesting victim communications.
Mimikatz / Pass-the-Hash Tooling Credential Theft · Publicly Available
Used for in-memory credential extraction (LSASS) and pass-the-hash lateral movement, allowing operators to move through Windows domains without needing plaintext passwords.
Poison Ivy / Gh0st RAT Publicly Available RATs · Occasional Use
Used occasionally alongside APT1's custom toolset when convenient; the group's overwhelming preference for bespoke backdoors over these common commodity RATs was itself a distinguishing forensic signature Mandiant used in its attribution analysis.
07
Indicators of Compromise Historical — archival only, all IPs and domains defanged
⚠ IOC HANDLING — All IPs and domains in this table are defanged. Reconstruct before use. HISTORICAL: this infrastructure was torn down within weeks of the February 2013 report; treat all entries as archival/research references only, not actionable current detection content. Reference URLs in Section 10 are NOT defanged.
Type Value / Description Source Date
MALWAREWEBC2 backdoor family (multiple variants)Mandiant "APT1" report2013-02-19
MALWAREBISCUIT backdoorMandiant "APT1" report2013-02-19
INFRA937+ identified C2 servers across 13 countries — full historical IP/domain/certificate appendix published separately by MandiantMandiant "APT1" report appendix2013-02-19
PERSONA"UglyGorilla" (Wang Dong), "SuperHard" (Mei Qiang) — named operator handles identified via forensic/OPSEC analysisMandiant; US DOJ indictment2013-02 / 2014-05
NOTEMandiant's original report included one of the largest public indicator releases of its time — MD5 hashes, FQDNs, X.509 certificates, and IP ranges — as a separate published appendix. Given the intervening 13 years and the group's confirmed 2013 infrastructure teardown, treat all of it as archival/historical. Consult the original Mandiant APT1 report and its appendix directly for the complete historical indicator set rather than any single indicator reproduced secondhand.
08
Analyst Assessment
Overall Threat LevelHIGH (Historical) — not currently an active tracked threat under this designation
Attribution ConfidenceHIGH
TrajectoryAssessed dormant/absorbed — no activity publicly attributed to this designation since 2013 exposure and the 2015–16 PLA restructuring
Most Dangerous Capability (Historical)Sustained, multi-year persistence enabling systematic harvesting of an entire economy's worth of strategic intellectual property rather than single high-value targets
Primary Intel GapWhich currently tracked Chinese APT clusters, if any, directly inherited Unit 61398 personnel, tooling, or mission after the 2015–16 restructuring — no public reporting definitively maps this succession
Ecosystem / Affiliated Groups
PLA Unit 61398 (legacy designation) PLA Strategic Support Force (post-2015 successor structure) Other China-nexus APT clusters (no confirmed operational linkage)

APT1's most important legacy is not any specific ongoing capability but the model it established: that a private company, using forensic malware analysis, infrastructure correlation, and operators' own OPSEC failures, could publicly and credibly attribute cyber-espionage activity to a specific unit of a specific nation's military — and that doing so could carry real policy consequences, up to and including a first-of-its-kind criminal indictment. Every subsequent high-confidence nation-state attribution report, and the entire "APTn"/vendor-designation naming ecosystem used industry-wide today, traces its lineage directly to this report.

Confidence that APT1 "went dark" rather than simply rebranded is moderate-to-high but not absolute: the group's rapid infrastructure teardown within weeks of exposure is well documented, and the 2015–2016 PLA restructuring that created the Strategic Support Force provides a plausible institutional explanation for a change in tracking designation rather than a cessation of capability. No public reporting, however, definitively traces Unit 61398 personnel or toolset lineage into a specific currently tracked Chinese APT cluster — this is a genuine, acknowledged intelligence gap rather than an assumption analysts have resolved.

The forward risk this profile represents is almost entirely historical and doctrinal rather than operational: organizations are not at meaningful risk from APT1's specific 2007–2013-era toolset or infrastructure today. Its ongoing relevance is as the foundational case study for understanding Chinese state-directed economic cyber-espionage doctrine, for training analysts in forensic attribution methodology, and as the direct historical antecedent of the modern public/private cyber-attribution ecosystem — including the 2014 indictment model the U.S. government has since repeated against other nation-state actors.

09
Defensive Recommendations
01
Deploy advanced anti-phishing controls with attachment detonation/sandboxing. APT1's near-total reliance on spear-phishing for initial access means link/attachment-based defenses remain the single highest-leverage control against this style of tradecraft.
Counters: T1566.001, T1566.002
02
Restrict and monitor LSASS access. Enable Credential Guard and LSASS protection (RunAsPPL) to blunt Mimikatz-style in-memory credential dumping.
Counters: T1003.001
03
Detect and block pass-the-hash lateral movement. Enforce restricted-admin RDP, disable NTLM where feasible, and monitor for authentication patterns consistent with pass-the-hash.
Counters: T1550.002, T1021.001
04
Monitor for masquerading executables. Alert on binaries with mismatched digital signatures or hashes relative to their claimed identity (e.g., a file named AcroRD32.exe that does not match Adobe's signed binary).
Counters: T1036.005
05
Baseline and alert on native-tool reconnaissance chains. Correlate sequences of net.exe, tasklist, ipconfig, and similar built-in commands run in unusual order or volume, since APT1-style operators deliberately minimize custom tooling during discovery to blend in.
Counters: T1087.001, T1135
06
Monitor mail-store access patterns for bulk extraction. Alert on anomalous, high-volume access to Exchange mailboxes or local .pst files outside normal user behavior — the signature of GETMAIL/MAPIGET-style bulk email theft.
Counters: T1114
07
Enforce data-loss prevention on outbound archive traffic. Flag or block large RAR/ZIP archives being staged and transferred to external destinations, particularly from file-share or engineering-document repositories.
Counters: T1560.001
08
Assume long dwell times and hunt accordingly. Given APT1's average 356-day (and up to 1,764-day) dwell times, threat-hunting programs should include retrospective log analysis reaching back a full year or more, not just recent-activity alerting.
Counters: General dwell-time/persistence posture
10
References URLs are NOT defanged — navigate directly
Mandiant
Accessed: 2026-08-29
CONTEMPORANEOUS REPORTING — 2013-02-19
Wikipedia
Accessed: 2026-08-29
US DOJ
Accessed: 2026-08-29
CONTEMPORANEOUS REPORTING — 2014-05-19
FBI
Accessed: 2026-08-29
Lawfare
Accessed: 2026-08-29
Lawfare
Accessed: 2026-08-29
Dark Reading
Accessed: 2026-08-29
Wikipedia
Accessed: 2026-08-29
Hedgehog Security
Accessed: 2026-08-29
EuRepoC
Accessed: 2026-08-29