US Cert Alert - Peoples Republic of China PRC Ministry of State Security APT40 Tradecraft in Action

This advisory outlines the tactics techniques and procedures employed by the state-sponsored cyber group APT40 also known as Kryptonite Panda GINGHAM TYPHOON Leviathan and Bronze Mohawk. The group believed to be associated with the Peoples Republic of Chinas Ministry of State Security has repeatedly targeted networks in various countries including Australia and the United States. The report provides details on the groups methods for initial access execution persistence privilege escalation defense evasion credential access discovery lateral movement collection exfiltration and command and control. It highlights the groups ability to rapidly exploit new vulnerabilities and compromised devices as operational infrastructure.