APT1
G0006
CHINA
COMMENT CREW
Threat IntelligenceAPTChinaApril 22, 2025

APT1 Threat Profile

PLA Unit 61398 threat group that systematically stole hundreds of terabytes of data from at least 141 organizations across 20 industries since 2006.

PLA Unit 61398 threat group that systematically stole hundreds of terabytes of data from at least 141 organizations across 20 industries since 2006. This profile is mapped to MITRE ATT&CK G0006 and covers attribution, tooling, targeting, and defensive recommendations based on observed campaigns.

Overview & Attribution

APT1 (also tracked as Comment Crew, Comment Panda) is a threat group attributed to China. The group primarily targets US, UK, critical infrastructure, defense, tech for intelligence collection and operational objectives aligned with state interests.

MITRE ATT&CK Reference

This group is tracked as G0006 in the MITRE ATT&CK framework. All techniques referenced in this report are mapped to ATT&CK for consistent threat modeling and detection engineering.

Arsenal & Tools

Known tools and malware associated with APT1 include:

Targeting & Operations

APT1 operations focus on US, UK, critical infrastructure, defense, tech. The group typically gains initial access through spear-phishing, exploitation of public-facing applications, or strategic web compromises before deploying custom implants for persistent access and data exfiltration.

Targeting Advisory

Organizations in the US sector should treat APT1 as a relevant threat and validate their detection coverage against the MITRE ATT&CK techniques listed below.

MITRE ATT&CK Mapping

Key techniques observed in APT1 operations:

Technique IDTechnique NameTactical Context
T1566.001T1566.001Observed in APT1 campaigns
T1059.001T1059.001Observed in APT1 campaigns
T1003.001T1003.001Observed in APT1 campaigns
T1074.001T1074.001Observed in APT1 campaigns

Full ATT&CK mapping: https://attack.mitre.org/groups/G0006/

Notable Campaigns

This threat group has been active in operations targeting US, UK, critical infrastructure, defense, tech. Security researchers have documented campaigns involving WEBC2 and other tools deployed against organizations in multiple countries. Attribution confidence varies by campaign, but consistent infrastructure and TTP overlap links activity to China-nexus operations.

Detection & Defense

Recommended defensive measures against APT1:

How Mjolnir Security Can Help

Defend Against APT1

Mjolnir Security provides tailored threat intelligence, detection engineering, and incident response services to help organizations defend against China-nexus threat actors.

Threat Intelligence Detection Engineering Incident Response Red Team Assessment Threat Hunting

Contact us: mjolnirsecurity.com

Written by: Mjolnir Security  |  Published: April 22, 2025