MITRE ATT&CK G0006
Aliases: APT1, Comment Crew, TG-8223
Official Attribution Source: U.S. Department of Justice Indictment (W.D. Pa., May 2014)

Key Facts

Jurisdiction
People's Republic of China
Geographic origin
Cases
1
Prosecution matters
Defendants
2
Indicted individuals
Sanctions
0
OFAC designations
  • Attributed Country: People's Republic of China.
  • ATT&CK Group Reference: G0006 (PLA Unit 61398).
  • Linked to 1 primary court prosecution records.
  • Identified 2 individually charged operatives.

Primary ATT&CK Techniques Employed

ATT&CK Techniques Mapped to PLA Unit 61398 Technique frequencies extracted from verified indictments for PLA Unit 61398. T1566.001 Spearphishing Attachment 1 incidents T1041 Exfiltration Over C2 Channel 1 incidents
Technique frequencies extracted from verified indictments for PLA Unit 61398.
ATT&CK Techniques Mapped to PLA Unit 61398
Technique Frequency
T1566.001 Spearphishing Attachment 1 incidents
T1041 Exfiltration Over C2 Channel 1 incidents

Prosecution Cases Attributed to This Actor

fugitive 2014-05-01

U.S. v. Sun Kailiang et al. (PLA Unit 61398 / APT1)

Historic first-ever criminal indictment against state military actors: five Chinese military officers in People's Liberation Army Unit 61398 charged with cyber espionage against Westinghouse, U.S. Steel, Alcoa, and the United Steelworkers union.

2 techniques View case →
OPERATIONAL DEFENSE

Targeted Defensive Hardening for PLA Unit 61398

Run Stack Audit →

Primary Initial Access Defense

Enforce hardware FIDO2 multi-factor authentication across all perimeter VPN, Citrix, and cloud data portals. Prohibit SMS or push-based MFA that can be bypassed via vishing or SIM swapping.

Lateral Movement Interception

Restrict internal SMB (port 445) and RPC traversal between workstation subnets. Implement tiered Active Directory administration so domain administrator credentials are never cached on endpoints.