Gold Open Source
ExplorePackagesVulnerabilitiesCWEsMCP ServersScan
Login
Gold Open Source

The authoritative source for production-ready open-source components. Every package, container image, AI model, and MCP server undergoes rigorous verification for security, malware, and license compliance.

Explore Gold

  • Explore Everything
  • Packages
  • Gold Certified Packages
  • Container Images
  • AI Models
  • MCP Servers
  • Agent Skills
  • Chip Manufacturers

Security Data & Tools

  • Scan Your Dependencies
  • Trending Threats
  • Threat RSS Feeds
  • CVE Database
  • Actively Exploited (KEV)
  • SGZ Zero-Days
  • CWE Index
  • MITRE ATT&CK
  • Malicious Packages
  • Security Glossary
  • Supply-Chain Report
  • Developers (API & Badge)
  • Chrome Extension
  • Credits & Data Sources

Products

  • The Platform
  • ESSCM
  • Portal
  • TPRM
  • OSM
  • Cowork
  • Code / Runner
  • Guard

Use Cases

  • Know Your Software
  • Auto-Fix Vulnerabilities
  • Asset Discovery
  • AI Governance
  • MCP Server Security
  • Supply Chain Compliance
  • Zero-Day Discovery
  • All Use Cases

Company

  • About
  • Pricing
  • Blog
  • Documentation
  • Safeguard Academy
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 Gold Open Source. All rights reserved.

Built with care bySafeguard
Home/ATT&CK/Groups/G0006
MITRE ATT&CK Group

APT1 (G0006)

Comment CrewComment GroupComment Panda
ShareXLinkedInRedditHN

[APT1](https://attack.mitre.org/groups/G0006) is a Chinese threat group that has been attributed to the 2nd Bureau of the People’s Liberation Army (PLA) General Staff Department’s (GSD) 3rd Department, commonly known by its Military Unit Cover Designator (MUCD) as Unit 61398. (Citation: Mandiant APT1)

▪Techniques used (23)

T1003.001LSASS MemoryT1057Process DiscoveryT1005Data from Local SystemT1550.002Pass the HashT1583.001DomainsT1560.001Archive via UtilityT1119Automated CollectionT1114.002Remote Email CollectionT1566.002Spearphishing LinkT1016System Network Configuration DiscoveryT1114.001Local Email CollectionT1588.001MalwareT1049System Network Connections DiscoveryT1585.002Email AccountsT1584.001DomainsT1036.005Match Legitimate Resource Name or LocationT1087.001Local AccountT1566.001Spearphishing AttachmentT1135Network Share DiscoveryT1059.003Windows Command ShellT1588.002ToolT1007System Service DiscoveryT1021.001Remote Desktop Protocol

▪Software used (17)

S0345SeasaltmalwareS0100ipconfigtoolS0017BISCUITmalwareS0119CachedumptoolS0029PsExectoolS0026GLOOXMAILmalwareS0121LslsasstoolS0012PoisonIvymalwareS0109WEBC2malwareS0002MimikatztoolS0008gsecdumptoolS0122Pass-The-Hash ToolkittoolS0025CALENDARmalwareS0057TasklisttoolS0039NettoolS0123xCmdtoolS0006pwdumptool
G0006on MITRE ATT&CK →

MITRE ATT&CK® is a registered trademark of The MITRE Corporation. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation.