Actor
APT31
6 sourced claims · 2 documents touched
Since [~2018], Chinese cyber actors known in the private sector as APT31 [OCR shows "AP 3"] have targeted personal e-mail accounts of senior US leadership, including officials in the Executive Office of the President and high-ranking officials across Executive Branch organizations, Congress, and the federal judiciary (p.1).
p.1As of 20 May, APT31 actors sent spear-phishing e-mails with tracking links to Gmail accounts of staffers associated with a presidential campaign; on 4 June, Google announced APT31 was targeting the campaign (p.1).
p.1APT31's use of tracking links suggests operators are mapping the target network for follow-on approaches, possibly tasking staffers' e-mail accounts in the Chinese military's signals-intelligence system; tracking links collect metadata (Internet activity, system information) usable to exploit accounts and identify other targets (p.1-2).
p.1
Since [OCR unclear] 2018, Chinese cyber actors known in the private sector as APT31 [OCR renders "AP 3"; identified as APT31 later on p.1] targeted personal email accounts of senior U.S. leadership, including officials in the Executive Office of the President, high-ranking officials in multiple Executive Branch organizations, Congress, and the federal judiciary (p.1).
p.1As of 20 May, APT31 actors had sent spear-phishing emails containing tracking links to Gmail accounts of staffers associated with a presidential campaign; on 4 June, Google announced APT31 was targeting the campaign (p.1).
p.1APT31's tracking-link method suggests mapping the target network for follow-on approaches, possibly including tasking campaign staffers' email accounts in the Chinese military's signals intelligence system for collection (p.1-2).
p.1