APT4 is a China-aligned espionage threat actor also tracked as Maverick Panda, SODIUM, and Salmon Typhoon. Microsoft maps SODIUM/Salmon Typhoon to a Chinese state-affiliated cluster that overlaps with APT4 and Maverick Panda. The actor is assessed as conducting cyber espionage rather than financially motivated crime. Observed activity links the group to reconnaissance on geopolitical and intelligence topics, technical research, translation of technical materials, and coding assistance. Reported interests have included intelligence agencies, regional threat actors, cybersecurity topics, and methods for hiding processes on compromised systems. The actor has also been associated with use of XMRig, indicating at least some observed overlap with unauthorized cryptomining tooling, though the broader body of reporting in the supplied facts characterizes the group primarily as an espionage actor. High-confidence reporting in the supplied facts supports Chinese state affiliation and reconnaissance-focused tradecraft, but does not provide a fuller, corroborated intrusion profile for APT4 specifically such as consistent victimology, malware set, or a detailed operational lifecycle. Known aliases include Maverick Panda, SODIUM, and Salmon Typhoon.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Attributed origin per open-source reporting.
2 malware families attributed to this actor across reporting.
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced only as another threat actor observed using XMRig.
China-linked nation-state threat actor listed in Microsoft's naming taxonomy mapping.
Referenced as a resurgent Chinese espionage group (no specific Pulse Secure tradecraft attributed in this text beyond general resurgence).
Listed as a China-linked named cluster; no additional operational detail provided in the content beyond inclusion in an APT group list.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.