Lumu Named Leader in GigaOm NDR Radar 2026

Already have an account? Sign in

Sign in

Group

G0065

Leviathan

Aliases

APT40, TEMP.Periscope, BRONZE MOHAWK, Kryptonite Panda, Gadolinium, Gingham Typhoon

Type

State-sponsored threat group (nation-state)

Target

Engineering Sectors, Government, Maritime industries, Naval Defense Contractors, Research Institutions

Malware

ISLANDDREAMS, MUDCARP, PHOTO, BADFLICK, custom web shells

Country

China China

IoCs on Maltiverse

Maltiverse provides updated IoCs for easy SIEM/SOAR/Firewall/EDR integration.

Who is Leviathan?

Leviathan is a Chinese state-sponsored cyber espionage group. Researchers link them directly to the Ministry of State Security (MSS). They operate primarily to support China’s naval modernization and the Belt and Road Initiative.

Unlike criminal groups seeking financial gain, Leviathan steals trade secrets. They target high-value engineering data, maritime research, and naval defense technology. They are highly active across the United States, Australia, and Southeast Asia.

Leviathan is highly opportunistic. They actively scan the internet for unpatched public-facing applications to gain an initial foothold. Once inside, they capture legitimate credentials and map the network. They establish long-term persistence to quietly siphon critical intellectual property over many months.

Leviathan’s Common Tactics and Tools

Leviathan uses rapid exploitation and customized malware to conduct espionage.

  • Public vulnerability exploitation: The group quickly weaponizes new vulnerabilities. They frequently target internet-facing systems like remote access portals and enterprise email servers.
  • SOHO router hijacking: Leviathan compromises small-office and home-office routers. They use these devices to mask their command and control traffic and blend in with normal internet usage.
  • Web shells and credential theft: Attackers deploy custom web shells onto compromised servers. They use these scripts to capture cleartext passwords, multi-factor authentication codes, and session tokens.
  • Living off the Land (LotL): Leviathan relies heavily on legitimate administrative tools. They use utilities like PowerShell to move laterally without triggering security alerts.

How to Defend Against Leviathan

Defending against Leviathan requires aggressive patch management, strict access controls, and deep network visibility.

  • Patch public-facing systems: Leviathan aggressively exploits known vulnerabilities. Use Lumu Discover to continuously monitor your attack surface. Prioritize patching remote access gateways, virtual private networks, and email servers.
  • Monitor web directories: Leviathan drops custom web shells on compromised servers. Implement File Integrity Monitoring (FIM) on public-facing web servers to detect unauthorized script creations or modifications immediately.
  • Audit WMI and PowerShell: The group uses Windows Management Instrumentation (WMI) to execute commands stealthily. Restrict PowerShell execution policies and configure endpoint detection to flag unusual WMI namespace activity. Feed these endpoint alerts directly into Lumu Defender to automate your response and instantly block any associated network threats.
  • Use network detection (NDR): Use tools like Lumu Defender to identify anomalous outbound connections. Detect traffic communicating with compromised SOHO routers, which Leviathan uses to blend in with normal internet noise.
  • Integrate threat intelligence: Use platforms like Lumu Maltiverse to stay updated on the latest Leviathan infrastructure. Block access to known malicious domains and IP addresses.

Join our pre-day 
workshop waitlist

By clicking “Submit Request” you agree to the Lumu Terms of Service and Privacy Policy.