logo

People’s Republic of China (PRC) Ministry of State Security APT40 Tradecraft in Action

ID: a3de7eb2-d4bf-5741-ab35-0c30189bf256

STIX ID: report--a3de7eb2-d4bf-5741-ab35-0c30189bf256

Feed Name: CISA Cybersecurity Advisories

Threat Score
90/100

Date Published: 2024-07-08

Date Updated: 2026-04-19

Author: CISA

...
...

This joint advisory from multiple national cybersecurity agencies details APT40 (a PRC state‑sponsored actor) activity against organizations in 2022, including two anonymized case studies where the group exploited internet‑facing applications and RCE vulnerabilities to deploy web shells, steal hundreds of credentials and session tokens (including MFA/JWT artifacts), move laterally, and exfiltrate sensitive data; the report maps observed TTPs to MITRE ATT&CK, provides IOCs and Sigma detection rules, and recommends patching, logging, segmentation and other mitigations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.