← Back to all campaigns
ActiveMITRE ATT&CK

Leviathan Australian Intrusions

Leviathan Australian Intrusions consisted of at least two long-term intrusions against victims in Australia by Leviathan, relying on similar tradecraft such as external service exploitation followed by extensive credential capture and re-use to enable privilege escalation and lateral movement. Leviathan Australian Intrusions were focused on exfiltrating sensitive data including valid credentials for the victim organizations.

First observedApr 1, 2022
Last observedSep 1, 2022
Attributed actors1
Source-backed events3
Attribution

Who has been linked to this activity

Each relationship retains its own confidence and source.

Source ReportedActive actor

Leviathan

Leviathan is a Chinese state-sponsored cyber espionage group that has been attributed to the Ministry of State Security's (MSS) Hainan State Security Department and an affiliated front company. Active since at least 2...

mitre-attckReview source
Activity

Campaign timeline

Every date says what it measures so catalog dates are not confused with publication dates.

Cataloged
Attribution

Leviathan attributed to this campaign

Attribution confidence: Source Reported.

Last observed
Campaign

Leviathan Australian Intrusions last observed

The campaign source marks this as the latest known activity date.

MITRE ATT&CKSource
First observed
Campaign

Leviathan Australian Intrusions first observed

The campaign source marks this as the beginning of the known activity window.

MITRE ATT&CKSource
About the context below

CVEs, techniques, malware, and indicators in the sections below are associated with an attributed actor. They are useful investigative context, but the campaign source does not necessarily link every item directly to this campaign.

Investigation context

What the attributed actors are known to use

Use this material to guide hunting and prioritization, then confirm each relationship against its cited source.

Malware and tools 17

  • BADFLICKMalware | Leviathan
  • BLACKCOFFEEMalware | Leviathan
  • China ChopperMalware | Leviathan
  • Cobalt StrikeMalware | Leviathan
  • DerusbiMalware | Leviathan
  • HOMEFRYMalware | Leviathan
  • MURKYTOPMalware | Leviathan
  • NanHaiShuMalware | Leviathan
  • OrzMalware | Leviathan
  • gh0st RATMalware | Leviathan
  • BITSAdminTool | Leviathan
  • EmpireTool | Leviathan

Indicators 0

No source-linked indicators are available.

Sources

Evidence behind this page

Open the original material before making an attribution or response decision.