G0018 · 12 ATT&CK techniques · 0 correlated reports

admin@338

Aliases: None listed

admin@338 is a China-based cyber threat group. It has previously used newsworthy events as lures to deliver malware and has primarily targeted organizations involved in financial, economic, and trade policy, typically using publicly available RATs such as PoisonIvy, as well as some non-public backdoors.

Open interactive actor investigation

ATT&CK techniques

Correlated CTI and IR reports

Continue the investigation