FireEye identified APT40 as a China-nexus espionage group active since at least 2013, targeting engineering, transportation, and defense organizations with a strong focus on maritime technologies and other sectors tied to China’s strategic interests. The group has used web server exploitation, spearphishing, web shells, credential theft, lateral movement, and legitimate platforms such as GitHub, Google, and Pastebin for command-and-control, while expanding targeting to countries relevant to the Belt and Road Initiative, including the U.S. and U.K.
Separate reporting alleged that APT40 is operated through a Hainan-based network tied to China’s Ministry of State Security (MSS), with front companies and recruitment activity linked to alleged intelligence officer Ding Xiaoyang. The broader reporting portrays APT40 as part of a larger Chinese state-directed cyber ecosystem in which responsibility for major offensive operations shifted from the PLA toward the MSS, supporting long-term espionage goals such as intellectual property theft, strategic intelligence collection, and rapid exploitation of newly disclosed vulnerabilities.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
12 events from the most recent confirmed update back to the earliest known activity.
Within a year of the December 2016 UUV seizure, FireEye observed APT40 masquerading as a UUV manufacturer and targeting universities engaged in naval research. FireEye linked this activity to the group's support for Chinese maritime objectives.
FireEye referenced a December 2016 incident in which China's People's Liberation Army Navy seized a U.S. Navy unmanned underwater vehicle in the South China Sea. The event was used as context for later APT40 targeting related to naval research.
Intrusion Truth claims that around 2015 the Chinese government moved the bulk of offensive cyber operations from the PLA to the Ministry of State Security. It links the shift to efforts to improve deniability after scrutiny of PLA-linked activity such as Unit 61398.
Intrusion Truth states that Cyb3rSleuth publicly identified Zhang Changhe in 2013 as a PLA-linked hacker. The article says Zhang Changhe worked as an assistant professor at the PLA Engineering University.
Intrusion Truth says a disgruntled PLA hacker identified as Wang wrote publicly in 2013 about conducting hacking for China. The article cites this as evidence of PLA-linked cyber activity during that period.
FireEye reported that APT40 had been active since at least 2013 and assessed its operations supported China's naval modernization effort. The group focused on engineering, transportation, and defense targets tied to maritime technologies.
A QQ group described as for 'internal members only' and later cited in research on an alleged APT40-linked network was created with 25 members. The group was used as part of the argument linking Ding Xiaoyang and others to Hainan state security structures.
A 2009 Renren exchange cited by Intrusion Truth said Ding Xiaoyang had started a new job with the Hainan Provincial Department of the Ministry of Public Security in Haikou. The article argues this may have been cover for Ministry of State Security work.
After the 2001 collision between a U.S. EP-3 aircraft and a Chinese F-8 fighter jet, Chinese hacktivists reportedly launched sustained DDoS attacks and website defacements against U.S. targets, with U.S. hacktivists retaliating against Chinese targets.
Intrusion Truth states that Hafnium and multiple Chinese APT groups concurrently exploited the Microsoft Exchange Server vulnerability. The article presents this as an example of overlapping Chinese state-linked and contractor activity.
Intrusion Truth published research claiming APT40 was operated through a Hainan-based front-company network and run by the Hainan department of the Ministry of State Security. The article identified Ding Xiaoyang as a likely operator or coordinator tied to that apparatus.
FireEye publicly reported on APT40, describing its maritime-focused espionage targeting, China-based indicators, and rapid weaponization of disclosed vulnerabilities. The company assessed with moderate confidence that APT40 is a state-sponsored Chinese cyber espionage actor.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
3 references tracked. Mallory keeps watching after this page renders.
intrusiontruth.wordpress.com
Open sourceintrusiontruth.wordpress.com
Open sourcefireeye.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.