Comment Crew, APT 1

Description

Also known as APT1, Comment Crew is an advanced persistent threat (APT) group with links to the Chinese military. The threat actors, which were active from roughly 2006 to 2010, managed to strike over 140 US companies in the quest for sensitive corporate and intellectual property data.

The group earned their name through their use of HTML comments to hide communication to the command-and-control servers. The usual attack vector was via spear-phishing campaigns utilizing emails which contained documents with names tailored for the potential victims, such as “ArmyPlansConferenceOnNewGCVSolicitation.pdf,” or “Chinese Oil Executive Learning From Experience.doc.”

This group may also be responsible for the Siesta campaign.

Names

NameName-Giver
Comment CrewSymantec
Comment PandaCrowdStrike
TG-8223SecureWorks
APT 1Mandiant
BrownFoxSymantec
Group 3Talos
Byzantine HadesUS State Department
Byzantine CandorUS State Department
Shanghai GroupSecureWorks
GIF89aKaspersky

Country

State-sponsored, 2nd Bureau of the People’s Liberation Army (PLA) General Staff Department’s (GSD) 3rd Department, commonly known by its Military Unit Cover Designator (MUCD) as Unit 61398

Motivation

  • Information theft and espionage

First Seen

2006

Observed Sectors

Observed Countries

Tools

Operations

Counter Operations

Information

Mitre Attack

Other Information

Uuid

b99367ed-e483-40a3-98d0-8d3a2102a4ab

Last Card Change

2021-05-21