Gold Open Source
ExplorePackagesVulnerabilitiesCWEsMCP ServersScan
Login
Gold Open Source

The authoritative source for production-ready open-source components. Every package, container image, AI model, and MCP server undergoes rigorous verification for security, malware, and license compliance.

Explore Gold

  • Explore Everything
  • Packages
  • Gold Certified Packages
  • Container Images
  • AI Models
  • MCP Servers
  • Agent Skills
  • Chip Manufacturers

Security Data & Tools

  • Scan Your Dependencies
  • Trending Threats
  • Threat RSS Feeds
  • CVE Database
  • Actively Exploited (KEV)
  • SGZ Zero-Days
  • CWE Index
  • MITRE ATT&CK
  • Malicious Packages
  • Security Glossary
  • Supply-Chain Report
  • Developers (API & Badge)
  • Chrome Extension
  • Credits & Data Sources

Products

  • The Platform
  • ESSCM
  • Portal
  • TPRM
  • OSM
  • Cowork
  • Code / Runner
  • Guard

Use Cases

  • Know Your Software
  • Auto-Fix Vulnerabilities
  • Asset Discovery
  • AI Governance
  • MCP Server Security
  • Supply Chain Compliance
  • Zero-Day Discovery
  • All Use Cases

Company

  • About
  • Pricing
  • Blog
  • Documentation
  • Safeguard Academy
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 Gold Open Source. All rights reserved.

Built with care bySafeguard
Home/ATT&CK/Groups/G1023
MITRE ATT&CK Group

APT5 (G1023)

Mulberry TyphoonMANGANESEBRONZE FLEETWOODKeyhole PandaUNC2630
ShareXLinkedInRedditHN

[APT5](https://attack.mitre.org/groups/G1023) is a China-based espionage actor that has been active since at least 2007 primarily targeting the telecommunications, aerospace, and defense industries throughout the U.S., Europe, and Asia. [APT5](https://attack.mitre.org/groups/G1023) has displayed advanced tradecraft and significant interest in compromising networking devices and their underlying software including through the use of zero-day exploits.(Citation: NSA APT5 Citrix Threat Hunting December 2022)(Citation: Microsoft East Asia Threats September 2023)(Citation: Mandiant Pulse Secure Zero-Day April 2021)(Citation: Mandiant Pulse Secure Update May 2021)(Citation: FireEye Southeast Asia Threat Landscape March 2015)(Citation: Mandiant Advanced Persistent Threats)

▪Techniques used (29)

T1059.001PowerShellT1136.001Local AccountT1070.006TimestompT1021.001Remote Desktop ProtocolT1654Log EnumerationT1685Disable or Modify ToolsT1583.005BotnetT1074.001Local Data StagingT1554Compromise Host Software BinaryT1056.001KeyloggingT1078.004Cloud AccountsT1560.001Archive via UtilityT1003.001LSASS MemoryT1003.002Security Account ManagerT1070.004File DeletionT1098.007Additional Local or Domain GroupsT1057Process DiscoveryT1070Indicator RemovalT1053.003CronT1059.003Windows Command ShellT1021.004SSHT1055Process InjectionT1505.003Web ShellT1049System Network Connections DiscoveryT1078.002Domain AccountsT1036.005Match Legitimate Resource Name or LocationT1070.003Clear Command HistoryT1083File and Directory DiscoveryT1190Exploit Public-Facing Application

▪Software used (13)

S0057TasklisttoolS0012PoisonIvymalwareS1113RAPIDPULSEmalwareS1050PcSharetoolS0002MimikatztoolS1104SLOWPULSEmalwareS1110SLIGHTPULSEmalwareS0007Skeleton KeymalwareS0039NettoolS1109PACEMAKERmalwareS0032gh0st RATmalwareS1108PULSECHECKmalwareS0104netstattool
G1023on MITRE ATT&CK →

MITRE ATT&CK® is a registered trademark of The MITRE Corporation. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation.