← Back to all threat actors

Leviathan

Also known as MUDCARP, Kryptonite Panda, Gadolinium, BRONZE MOHAWK, TEMP.Jumper, APT40, TEMP.Periscope, Gingham Typhoon
Tracked as G0065

Leviathan is a Chinese state-sponsored cyber espionage group that has been attributed to the Ministry of State Security's (MSS) Hainan State Security Department and an affiliated front company. Active since at least 2009, Leviathan has targeted the following sectors: academia, aerospace/aviation, biomedical, defense industrial base, government, healthcare, manufacturing, maritime, and transportation across the US, Canada, Australia, Europe, the Middle East, and Southeast Asia.

How we source and review actor profiles
Motivation
nation-state
Attributed nexus
CN
Sectors
maritime, defense, government, technology
Status
Active

Activity timeline

A dated ledger of actor-claimed victims, campaigns, indicators, identity mappings, relationships, and CVE links. Each date states what it measures. For extensive leak-site histories, victim entries are limited to the 100 most recent distinct listings.

Cataloged
IdentityAlias: MUDCARP

Reviewed identity mapping approved on this date.

Cataloged
IdentityAlias: Kryptonite Panda

Reviewed identity mapping approved on this date.

Cataloged
IdentityAlias: Gadolinium

Reviewed identity mapping approved on this date.

Cataloged
IdentityAlias: BRONZE MOHAWK

Reviewed identity mapping approved on this date.

Cataloged
IdentityAlias: TEMP.Jumper

Reviewed identity mapping approved on this date.

Cataloged
IdentityAlias: APT40

Reviewed identity mapping approved on this date.

Cataloged
IdentityAlias: TEMP.Periscope

Reviewed identity mapping approved on this date.

Cataloged
IdentityAlias: Gingham Typhoon

Reviewed identity mapping approved on this date.

Cataloged
IdentityTracking identifier: G0065

Reviewed identity mapping approved on this date.

Cataloged
CVECVE-2017-11882 linked to this actor
Cataloged
CVECVE-2019-0604 linked to this actor
Cataloged
CVECVE-2019-19781 linked to this actor
Cataloged
CVECVE-2020-0688 linked to this actor
Cataloged
CVECVE-2021-26084 linked to this actor
Cataloged
CVECVE-2021-31207 linked to this actor
Last observed
CampaignLeviathan Australian Intrusions

Leviathan Australian Intrusions consisted of at least two long-term intrusions against victims in Australia by Leviathan, relying on similar tradecraft such as external service exploitation foll…

Identity and attribution

Exact names and tracking identifiers resolve to this canonical profile. Rebrands, affiliations, and overlapping clusters remain separate confidence-rated relationships.

Name map

LeviathanCanonical Name
APT40Alias
BRONZE MOHAWKAlias
GadoliniumAlias
Gingham TyphoonAlias
Kryptonite PandaAlias
MUDCARPAlias
TEMP.JumperAlias
TEMP.PeriscopeAlias
G0065Tracking Id

Loading CVEs, techniques, indicators, malware, victims, and activity...