logo

APT40

ID: 0c2e99d8-c756-5211-ade7-4b331df94cd7

STIX ID: report--0c2e99d8-c756-5211-ade7-4b331df94cd7

Feed Name: Brandefense Blog

Threat Score
90/100

Date Published: 2026-01-13

Date Updated: 2026-04-27

Author: BRANDEFENSE

...
...

APT40 is a long-running, China-linked cyber-espionage group that systematically targets maritime, naval, defense manufacturers, shipbuilders, research institutions, and related government entities. The report outlines APT40's objectives and tradecraft — tailored spearphishing and impersonation, exploitation of internet-facing vulnerabilities, use of custom and lightweight remote access tools (notably ISLANDDREAMS and MUDCARP), persistence via registry keys and scheduled tasks, encrypted HTTPS C2 with fallback domains, and low-volume exfiltration — and warns that the group is expanding beyond maritime targets to aerospace, advanced manufacturing, and additional government agencies.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.