admin@338

APT / StateG0018
Origin🇨🇳 China
Techniques (MITRE ATT&CK)12
SourceMITRE ATT&CK
State sponsor: ChinaAttribution confidence: 50%Target categories: Government, Private sector, Civil society
Targeted regions: Hong Kong · United States
Also known as:G0018MAGNESIUMTeam338

Vexday analysis

Grupo de ameaça persistente avançada (APT) de origem chinesa, rastreado pelo MITRE ATT&CK como G0018, o admin@338 tem como característica o uso de eventos de grande repercussão midiática como isca para distribuição de malware. Suas operações têm como alvo prioritário organizações ligadas a políticas financeiras, econômicas e comerciais, empregando ferramentas de acesso remoto (RATs) de uso público, como o PoisonIvy, além de backdoors não públicos. O grupo possui 12 técnicas documentadas na base ATT&CK e 1 CVE atribuída.

Attack chain

Plausible scenario built from the group's real techniques, ordered by the phases of an attack. Each step shows how the group typically operates.

Arsenal severity34
Impact: High
T1566.001T1059.003ENTRYInitial accessSpearphishingAttachmentEXECExecutionWindows CommandShellDISCDiscoverySystem ServiceDiscovery

Illustrative chain derived from techniques documented in MITRE ATT&CK — it does not represent a specific past attack. Severity summarizes the known arsenal (kill-chain coverage, actively exploited CVEs, techniques).

Exploited vulnerabilities 1

CVEs this group is known to exploit, per MITRE ATT&CK. Ordered by real-world severity.

admin@338 uses real techniques and exploits real flaws. TrueHacking's AI Autonomous Pentest simulates these attacks against your infrastructure and brings more security to your application.

Explore the AI Autonomous Pentest →