Skip to content
Deep Dive high defensemaritimeacademiaGovernmenttelecommunications

APT40: China's Maritime Espionage Machine and Its Playbook for 2026

Few threat actors illustrate China’s intelligence collection priorities as clearly as APT40. Where APT29 chases diplomatic cables and APT41 funds state operations through cybercrime, APT40 has a single, coherent mandate: steal everything related to maritime power, naval technology, and regional influence in the Indo-Pacific. The group has operated continuously since at least 2013, survived attribution and indictments, absorbed disruption operations, and continued producing intelligence of direct value to China’s military and strategic planners.

A July 2024 joint advisory from CISA, the FBI, the Australian Signals Directorate, and the NCSC provided the most detailed public attribution to date: APT40 operates under the direction of the Hainan State Security Bureau, a provincial office of China’s Ministry of State Security. The advisory documented specific tradecraft, infrastructure, and a key operational characteristic that security teams need to understand in 2026: APT40 moves faster on newly disclosed CVEs than most patching cycles can accommodate.

Who APT40 Is

The group goes by several tracking names across vendors. Mandiant tracks it as APT40. Microsoft uses GADOLINIUM, then shifted to Silk Typhoon. Crowdstrike uses Kryptonite Panda. Proofpoint tracks a partially overlapping cluster as TA423 and Red Ladon. The shared designations reflect consistent infrastructure, tooling, and targeting patterns across multiple vendor observation windows — this is the same operational group assessed with high confidence to be Hainan State Security Bureau’s contracted offensive capability.

APT40 is not a traditional military cyber unit. The Hainan SSB model — documented in the 2024 advisory — uses a front company, Hainan Xiandun Technology Development Co., Ltd., as a contractor. Researchers and operators linked to the front company were indicted by the US Department of Justice in 2021. Four Chinese nationals were named: Wu Shurong and three others with ties to the Hainan SSB’s Technical Reconnaissance Bureau. The indictment is notable not for producing extradition — that will not happen — but for the level of operational detail it confirmed.

The use of a front company with cultivated civilian personnel rather than uniformed military officers gives the SSB plausible deniability and access to a broader talent pool. It also means the group’s operators are researchers and engineers by background, not career military intelligence officers. This shapes the group’s approach to capability development.

What APT40 Targets

The targeting mandate centers on five domains that directly serve Chinese strategic planning:

Naval and maritime technology. Shipbuilding contractors, naval research institutions, manufacturers of marine propulsion and sonar systems, and defense companies involved in undersea systems. The South China Sea territorial dispute has been a consistent driver: China needs to understand the naval capabilities of the states disputing its claims, and building that picture requires continuous intelligence collection on their shipbuilding programs, weapons systems, and operational doctrine.

Academic and research institutions. Universities with strong marine science, oceanography, or naval architecture programs are consistent targets. Academic networks tend to have weaker security than defense contractors and offer access to research data and faculty with dual civilian-military roles. US, Australian, and European maritime universities have all been documented as targets.

Regional Pacific governments. Pacific Island nations are disproportionate targets relative to their size. China’s competition for regional influence in the Pacific — against both the US and Australia — requires understanding the political dynamics and foreign policy positions of these small states. Compromising their government networks provides visibility into diplomatic communications and signals how they are likely to vote on issues like Taiwan and South China Sea territorial claims.

Telecommunications. Regional telcos in the Asia-Pacific region provide persistent access to communications flowing through regional infrastructure. Compromised telco backbone equipment gives collection capabilities that supplement targeted intrusion operations.

Energy companies with Indo-Pacific exposure. Energy companies operating in the South China Sea region, particularly those involved in offshore energy extraction in disputed waters, are targeted for both intelligence and potential leverage.

The CVE Exploitation Playbook

The 2024 joint advisory made an operational point that deserves emphasis: APT40 conducts regular reconnaissance of target networks and prioritizes rapid exploitation of newly disclosed vulnerabilities, particularly in widely deployed products like Microsoft Exchange, Atlassian Confluence, Apache Log4j, and network perimeter devices (VPNs, firewalls, remote access gateways).

The advisory included a case study that illustrates the tempo. When a proof-of-concept for a public-facing vulnerability was released, APT40 was observed testing the exploit against the advisory authors’ own honeypot networks within hours. Against real targets, the group has demonstrated exploitation within days of CVE disclosure on multiple occasions.

This tempo creates a specific structural problem for defenders: APT40 operates within the gap between patch release and patch deployment. Enterprise patch cycles for complex systems like Exchange or Confluence frequently run two to four weeks. APT40 is inside networks before the patch cycle closes. The implication is that for organizations in APT40’s target set, detection and response capability matters more than patch timing, because the exploitation will sometimes occur before patching is possible.

The rapid exploitation focus shapes how APT40 gains initial access. The group is not primarily a spear-phishing actor for initial access — though phishing is used for subsequent payload delivery and lateral movement. Initial access frequently comes through internet-facing services: web applications, VPN concentrators, email gateways, and collaboration platforms. Anything that is internet-exposed and running software with a recent public CVE is a candidate.

Technical Tradecraft

AIRBREAK is a JavaScript-based backdoor delivered via compromised third-party websites. The malware uses legitimate online services — specifically, sites that allow user-generated content and document sharing — as command-and-control channels. This living-off-the-legitimate-internet approach means C2 traffic blends with normal web browsing behavior and is difficult to block without disrupting business operations.

FRESHFIRE is a .NET-based dropper observed in more recent campaigns, used to deploy secondary payloads and establish persistence through scheduled tasks and registry modifications.

LOWBALL is a cloud-storage-based backdoor that uses Dropbox’s API for C2 communication. The same legitimate-service blending logic applies: Dropbox traffic is allowed through most enterprise firewalls, and TLS encryption prevents content inspection.

More recently observed tooling includes modified versions of publicly available red team frameworks — Cobalt Strike derivatives and open-source alternatives — combined with living-off-the-land techniques using built-in Windows tools (certutil, bitsadmin, mshta, regsvr32) to avoid triggering endpoint detection rules.

The group uses web shells as persistent staging points on internet-facing servers after initial exploitation. Web shells on Exchange servers, Confluence instances, or WordPress-based sites in target organizations’ networks provide reliable reentry points even after initial backdoors are discovered and removed.

Operational security discipline is inconsistent. The 2021 indictment and subsequent tracking reflect a group that sometimes makes operational security errors — reusing infrastructure, allowing attribution clustering across campaigns — while being effective at evading detection within target networks for extended periods. The group’s persistence in networks is measured in months; dwell time before detection has historically been long.

The Hainan Connection and Contractor Model

The front company model has specific defensive implications. Contractor-run operations tend to have different operational rhythms than military cyber units. Contractors work against deliverable-based tasking, which means collection priorities can shift based on what the SSB clients need at a given time. The group has shown the ability to pivot targeting rapidly when strategic priorities shift — when the South China Sea situation changes, when Taiwan Strait tensions increase, or when a specific state becomes more diplomatically significant.

The contractor model also means the group likely has limited visibility into what other Chinese cyber operations are running against the same targets. APT40, APT41, and other Chinese state-sponsored actors have been observed in the same target networks simultaneously, often without apparent coordination. This creates detection opportunities: multiple overlapping intrusion clusters in the same network is a signal that the network is high-value and that detection of one cluster should trigger a broader hunt.

2026 Threat Posture

Several factors make APT40 more relevant in 2026 than in prior years.

The Indo-Pacific competition has intensified. The strategic competition between China and the United States, combined with Australia’s AUKUS positioning and increased security cooperation among Pacific Island nations aligned with the West, has raised the intelligence collection value of organizations in APT40’s traditional target set. Higher collection requirements typically translate to increased operational tempo.

The attack surface has expanded. The shift to cloud infrastructure and the proliferation of internet-facing SaaS applications has created more rapid-exploitation opportunities for the group. Organizations that moved legacy systems to cloud-hosted equivalents often created new external attack surfaces without corresponding security hardening.

AI and semiconductor research is an emerging target. Consistent with broader MSS collection priorities documented in 2025-2026 reporting, APT40-adjacent activity has been observed in organizations involved in AI research and semiconductor supply chains, particularly in the Asia-Pacific region. Maritime applications of AI — autonomous underwater vehicles, AI-enabled sonar processing, autonomous surface vessels — intersect the group’s traditional mandate with newer collection requirements.

Supply chain approach is maturing. The group has moved beyond direct network intrusion in some campaigns, targeting managed service providers, software vendors, and technology suppliers to their actual intelligence targets. Compromising an MSP that manages IT for a shipbuilding contractor provides access to the contractor network without requiring direct exploitation.

Defensive Priorities for Targeted Organizations

Organizations in defense contracting, maritime technology, academic research, regional government, or Pacific-facing telecommunications should treat APT40 as a persistent threat requiring active defensive posture, not just passive security controls.

Internet attack surface reduction is the highest-priority control. Every internet-facing service is a potential APT40 initial access vector. Application inventory, aggressive patching of internet-exposed services, and removal of unnecessary external exposure should be treated as ongoing operational requirements, not quarterly compliance exercises.

Assume rapid CVE exploitation. For CVEs rated critical against products in APT40’s exploitation pattern — Exchange, Confluence, Citrix, Fortinet, Ivanti, Cisco — assume exploitation within 72 hours of public PoC availability. Detection and response capability for post-exploitation activity is required because patching within that window is not reliably achievable.

Web shell detection and hunting. Persistent web shells on internet-facing servers are a consistent APT40 mechanism. Web shell detection should be on continuously, with alerting on new files in web directories and execution of processes spawned by web server processes. This is one of the highest-yield detections for this group.

Monitor legitimate cloud service C2 channels. AIRBREAK and LOWBALL use Dropbox and other cloud services for C2. Baseline what cloud service traffic looks like from server infrastructure, and alert on unexpected cloud storage API calls from servers that have no business reason to use those services.

Threat intelligence-driven hunt for overlapping intrusions. If APT40 indicators are found in your network, assume other Chinese cyber operators may also be present. Commission a broader hunt before concluding remediation.

The group has operated effectively for over a decade against a well-resourced set of adversarial intelligence services. It will continue operating in 2026 and beyond. The targets are stable, the mandate is clear, and the operational model is proven. Organizations in the target set need to be prepared for an adversary that will use their own internet-facing vulnerabilities against them faster than most patch cycles run.