What is Unit 61398 and what is their mission?

Published by Charlie Davidson on

What is Unit 61398 and what is their mission?

PLA Unit 61398

People’s Liberation Army Unit 61398
Branch People’s Liberation Army Strategic Support Force
Type Cyber force
Role Cyber warfare Electronic warfare
Garrison/HQ Tonggang Road, Pudong, Shanghai

What does APT1 stand for?

Advanced Persistent Threat 1
Advanced Persistent Threat 1 (APT1)

What type of attack was Titan Rain?

Titan Rain was a string of cyber operations that compromised a number of agencies within the U.S. and UK government. Chinese state-sponsored actors are suspected of breaching the unclassified networks of the U.S. Departments of State, Homeland Security, and Energy, and UK defense and foreign ministries.

Is APT1 active?

APT1 is a China-based cyber-espionage group, active since mid-2006. It is believed to be a part of the 2nd Bureau of the People’s Liberation Army (PLA) General Staff Department’s (GSD) 3rd Department. Since 2006, the APT1 has compromised over 140+ organizations spanning 20 strategically important industries.

What are apt groups?

An advanced persistent threat (APT) is a stealthy threat actor, typically a nation state or state-sponsored group, which gains unauthorized access to a computer network and remains undetected for an extended period.

What is the threat group name for China?

APT1 is a Chinese threat group that has been attributed to the 2nd Bureau of the People’s Liberation Army (PLA) General Staff Department’s (GSD) 3rd Department, commonly known by its Military Unit Cover Designator (MUCD) as Unit 61398. APT12 is a threat group that has been attributed to China.

How many apt groups are there?

Since then, these organisations have identified more than 150 APT groups globally. Thanks to these reports, the industry is not only aware of the evolving threats, but now also has details on their tactics, techniques and procedures.

What are the tactics techniques and procedures Ttps deployed by APT1?

The term Tactics, Techniques, and Procedures (TTP) describes an approach of analyzing an APT’s operation or can be used as means of profiling a certain threat actor. The word Tactics is meant to outline the way an adversary chooses to carry out his attack from the beginning till the end.

Is Titan Rain An example of a Trojan horse?

The Titan Rain attackers, operating out of the Guangdong province of China, used Trojan horses to infiltrate systems, hijacked portions of hard drives in target systems to use for file encryption, erased their electronic fingerprints when finished, and left a reentry beacon to facilitate easy access at a later time.

What is APT38?

APT38 is a financially-motivated threat group that is backed by the North Korean regime. The group mainly targets banks and financial institutions and has targeted more than 16 organizations in at least 13 countries since at least 2014.

Why are apt attacks more successful?

Because of the level of effort needed to carry out such an attack, APTs are usually leveled at high value targets, such as nation states and large corporations, with the ultimate goal of stealing information over a long period of time, rather than simply “dipping in” and leaving quickly, as many black hat hackers do …

Who are the people behind the code 61398?

“UglyGorilla,” “KandyGoo,” and “WinXYHappy” are some of the aliases used by the Chinese accused of hacking U.S. companies on Monday. The men behind these handles are officers of the People’s Liberation Army (PLA) under a unit known simply by the code 61398.

What do we know about the Chinese 61398?

Little is confirmed about the mysterious unit 61398, a section that the Chinese authorities have not officially acknowledged. The Chinese defense ministry said the country’s military “has never supported any hacker activities.”

When did Mandiant first report on the APT?

We first published details about the APT in our January 2010 M-Trends report. As we stated in the report, our position was that “The Chinese government may authorize this activity, but there’s no way to determine the extent of its involvement.”

What do we know about China’s shadowy army unit 61398?

Unit 61398 was given a special fiber optic communication infrastructure by state-owned enterprise China Telecom in the name of national defense, Mandiant reported. The accused Chinese hackers reportedly use spear-phishing to hack into companies.

Categories: Popular lifehacks