CSIDB logo
Threat actor

APT35

Attribution profile

Type
Nation State
Location
China
Known incidents
3 incidents
First seen
2020-01-23
Last seen
2020-07-07
Updated
2026-08-01 04:51
Aliases
3 aliases

STIX characteristics

Threat actor characteristics are available to members.

Profile narrative

The threat actor tracked as THE0TIME is also known by the aliases Charming Kitten and APT35. Public reporting associates the group with a Chinese origin, noting its location as China. The actor has been observed targeting telecommunications, healthcare, and aviation sectors across multiple regions.

In a July 2020 intrusion against Virgin Mobile KSA, the actors exploited an unpatched Microsoft Exchange vulnerability to gain initial access to the office network. Once inside, they used the ADRecon tool to extract password hashes from the domain controller. They then deployed PowerShell‑based malware and implanted web shells to maintain persistent presence. The stolen data, including employee emails and internal reports, was offered for sale on dark web forums. In April 2020 THE0TIME claimed responsibility for a breach of Huiying Medical Technology, where source code and experimental data for an AI‑assisted COVID‑19 detection system were exfiltrated. The actors advertised the stolen intellectual property for four Bitcoin.

Earlier in January 2020, cyber activity attributed to sources that included China attempted to disrupt flight paths at an Israeli international airport during a high‑profile diplomatic event. The attempts were repelled by national defenses, but the activity showed an attempt to interfere with flight paths. Across these incidents the actor’s tooling consistently relies on exploiting publicly known vulnerabilities, leveraging credential‑dumping utilities, and employing PowerShell scripts combined with web shells for long‑term access. No public source attributes the group to a specific criminal consortium; the available information only confirms the aliases and the geographic nexus to China. The observed operations include the sale of stolen credentials and intellectual property on underground markets as well as attempts to disrupt aviation services. These representative operations illustrate the actor’s capability to move from initial intrusion via Exchange flaws to data exfiltration and persistence mechanisms.

Incidents

Attributed incidents are available to members.

3 incidents
CSIDB