← Back to all threat actors

APT5

Also known as Mulberry Typhoon, MANGANESE, BRONZE FLEETWOOD, Keyhole Panda, UNC2630
Tracked as G1023

APT5 is a China-based espionage actor that has been active since at least 2007 primarily targeting the telecommunications, aerospace, and defense industries throughout the U.S., Europe, and Asia. APT5 has displayed advanced tradecraft and significant interest in compromising networking devices and their underlying software including through the use of zero-day exploits.

How we source and review actor profiles
Motivation
nation-state
Status
Active

Activity timeline

A dated ledger of actor-claimed victims, campaigns, indicators, identity mappings, relationships, and CVE links. Each date states what it measures. For extensive leak-site histories, victim entries are limited to the 100 most recent distinct listings.

Cataloged
IdentityTracking identifier: G1023

Reviewed identity mapping approved on this date.

Cataloged
IdentityAlias: Mulberry Typhoon

Reviewed identity mapping approved on this date.

Cataloged
IdentityAlias: MANGANESE

Reviewed identity mapping approved on this date.

Cataloged
IdentityAlias: BRONZE FLEETWOOD

Reviewed identity mapping approved on this date.

Cataloged
IdentityAlias: Keyhole Panda

Reviewed identity mapping approved on this date.

Cataloged
IdentityAlias: UNC2630

Reviewed identity mapping approved on this date.

Last observed
CampaignSPACEHOP Activity

SPACEHOP Activity is conducted through commercially leased Virtual Private Servers (VPS), otherwise known as provisioned Operational Relay Box (ORB) networks. The network leveraged for SPACEHOP Activity enabled China-nexus cyber threat…

Identity and attribution

Exact names and tracking identifiers resolve to this canonical profile. Rebrands, affiliations, and overlapping clusters remain separate confidence-rated relationships.

Name map

APT5Canonical Name
BRONZE FLEETWOODAlias
Keyhole PandaAlias
MANGANESEAlias
Mulberry TyphoonAlias
UNC2630Alias
G1023Tracking Id

Loading CVEs, techniques, indicators, malware, victims, and activity...