Leviathan, APT 40, TEMP.Periscope

Description

(FireEye) FireEye is highlighting a cyber espionage operation targeting crucial technologies and traditional intelligence targets from a China-nexus state sponsored actor we call APT40. The actor has conducted operations since at least 2013 in support of China’s naval modernization effort. The group has specifically targeted engineering, transportation, and the defense industry, especially where these sectors overlap with maritime technologies. More recently, we have also observed specific targeting of countries strategically important to the Belt and Road Initiative including Cambodia, Belgium, Germany, Hong Kong, Philippines, Malaysia, Norway, Saudi Arabia, Switzerland, the United States, and the United Kingdom. This China-nexus cyber espionage group was previously reported as TEMP.Periscope and TEMP.Jumper.

Also see Hafnium.

Names

NameName-Giver
LeviathanCrowdStrike
Kryptonite PandaCrowdStrike
APT 40Mandiant
TEMP.PeriscopeFireEye
TEMP.JumperFireEye
Bronze MohawkSecureWorks
MudcarpiDefense
GadoliniumMicrosoft
ATK 29Thales
ITG09IBM
TA423Proofpoint
Red LadonPWC
Gingham TyphoonMicrosoft
ISLANDDREAMSGoogle
Jumper TaurusPalo Alto

Country

State-sponsored, Ministry of State Security, Hainan province

Motivation

  • Information theft and espionage

First Seen

2013

Observed Sectors

Observed Countries

Tools

Operations

Counter Operations

Information

Mitre Attack

Other Information

Uuid

b106313a-d204-4d9f-866b-e750a98d0e06

Last Card Change

2025-06-27