admin@338
Also known as: admin338, g0018, magnesium, team338, temper panda
[admin@338](https://attack.mitre.org/groups/G0018) is a China-based cyber threat group. It has previously used newsworthy events as lures to deliver malware and has primarily targeted organizations involved in financial, economic, and trade policy, typically using publicly available RATs such as [PoisonIvy](https://attack.mitre.org/software/S0012), as well as some non-public backdoors. (Citation: FireEye admin@338)
Most affected countries
No data yet.
Most affected sectors
No data yet.
Priority mitigations
MITRE ATT&CK mitigations that cover the most techniques used by this group.
- Execution Prevention (3 techniques covered)
- User Training (2 techniques covered)
- User Account Management (1 techniques covered)
- Restrict Web-Based Content (1 techniques covered)
- Restrict File and Directory Permissions (1 techniques covered)
- Operating System Configuration (1 techniques covered)
- Network Intrusion Prevention (1 techniques covered)
- Behavior Prevention on Endpoint (1 techniques covered)
MITRE ATT&CK techniques
Recent victims
No data yet.
Claims are published by the criminal groups themselves and are unverified until the organisation or the press confirms them. Names of natural persons (sole traders, individual professionals) are anonymised under the GDPR. We never link to leak sites or stolen data. To request the removal or anonymisation of an entry, contact the site administrator.
Sources: RansomLook (CC BY 4.0), MITRE ATT&CK®, MISP Galaxy, Google News.