LLMpediaThe first transparent, open encyclopedia generated by LLMs

Unit 61398

Note: This article was automatically generated by a large language model (LLM) from purely parametric knowledge (no retrieval). It may contain inaccuracies or hallucinations. This encyclopedia is part of a research project currently under review.
Article Genealogy
Parent: Unit 8200 Hop 6 terminal

This article was accepted into the corpus but its outbound wikilinks were never NER-processed — typical at the deepest BFS hop or when the run's entity cap was reached. No expansion funnel to show.

Unit 61398
Unit nameUnit 61398
Native name中国人民解放军第三十二集团军网络行动部队 (commonly reported)
Active2006–present (reported)
CountryPeople's Republic of China
BranchPeople's Liberation Army
RoleCyber espionage, signals intelligence (reported)
GarrisonShanghai (reported)
NicknameAPT1 (attributed by private firms)

Unit 61398

Unit 61398 is an organization widely reported by intelligence analysts, cybersecurity firms, and media to conduct state-linked cyber intrusion and cyber espionage operations attributed to the People's Liberation Army. Coverage by entities including Mandiant, Symantec, CrowdStrike, FireEye, and reporting in outlets such as The New York Times, The Washington Post, and The Guardian situates the unit within broader discussions involving National Security Agency, GCHQ, Five Eyes, US Cyber Command, and other national cyber capabilities. Investigations and indictments by authorities like the United States Department of Justice and analyses by researchers at Harvard University, Stanford University, and Carnegie Mellon University have shaped public understanding of the unit.

Overview

Analyses by firms including Mandiant (report "APT1"), FireEye, Symantec, Kaspersky Lab, and CrowdStrike describe a persistent threat actor linked to a PLA unit based in Shanghai. Reporting in The New York Times, Reuters, Bloomberg, and The Wall Street Journal cites alleged long-term intrusions targeting entities such as Boeing, United Technologies Corporation, Lockheed Martin, Northrop Grumman, Raytheon, ExxonMobil, Shell plc, and Siemens. Government statements from US Department of Justice, UK National Cyber Security Centre, and Australian Signals Directorate have echoed private-sector findings, while debates involve analysis from think tanks like Atlantic Council, RAND Corporation, CSIS, and International Institute for Strategic Studies.

Organizational Structure and Location

Open-source reporting places the unit within the PLA's organizational reforms that include entities such as the PLA General Staff Department (prior to reorganization), the PLA Strategic Support Force, and units associated with the People's Liberation Army Third Department. Investigations by Mandiant, Recorded Future, and academic researchers have pointed to facilities in Pudong, Shanghai, and nearby industrial districts. Analysts from Oxford Internet Institute, Johns Hopkins University, and MITRE Corporation have attempted to map personnel, infrastructure, and logistical links to state research institutes and companies like China Telecom, China Unicom, and Huawei Technologies (cited in broader supply-chain analyses), while legal documents from US District Court for the Eastern District of Virginia and indictments name individuals allegedly associated with the unit.

Known Operations and Targets

Attributions by Mandiant, F-Secure, Kaspersky Lab, and Symantec describe campaigns targeting sectors including aerospace, energy, telecoms, maritime, and manufacturing. Reported victims include multinational corporations such as Boeing, General Electric, Schlumberger, Halliburton, General Motors, ABB Ltd, ThyssenKrupp, and Alstom. State and research institutions like NASA, National Oceanic and Atmospheric Administration, European Organization for Nuclear Research, Max Planck Society, and University of California campuses have been cited in broader cyber espionage reporting. Techniques described by MITRE ATT&CK, ENISA, NIST, and private firms include spear-phishing linked to known campaigns against World Bank, United Nations, International Monetary Fund, and corporate intellectual property repositories.

Attribution and International Response

Attribution efforts by Mandiant, FireEye, CrowdStrike, and national agencies including FBI, NSA, US Cyber Command, UK National Cyber Security Centre, and Australian Signals Directorate led to public statements and diplomatic démarches between United States Department of State and Ministry of Foreign Affairs of the People's Republic of China. High-profile indictments by the United States Department of Justice alleged involvement by specific personnel and precipitated diplomatic responses involving White House officials and meetings at forums such as ASEAN Regional Forum and G20 Summit discussions on cybersecurity norms. Multilateral institutions including United Nations General Assembly and OECD have hosted debates about state behavior in cyberspace shaped by these cases.

The United States Department of Justice issued indictments alleging economic espionage, leading to charges filed in federal courts and asset-related actions. Some corporations pursued civil litigation invoking statutes such as the Economic Espionage Act of 1996 and the Computer Fraud and Abuse Act. Financial and trade responses involved scrutiny by Committee on Foreign Investment in the United States and congressional hearings before the United States House Committee on Armed Services and the United States Senate Select Committee on Intelligence. Sanctions and export controls on entities linked to advanced technologies have been considered in policy reviews at the United States Department of Commerce and implemented in part through Bureau of Industry and Security rulemaking.

Cybersecurity Research and Public Reporting

Major reports include the Mandiant "APT1" report and follow-up technical analyses by FireEye, CrowdStrike, Symantec, Kaspersky Lab, Trend Micro, Palo Alto Networks, Cisco Talos, Recorded Future, F-Secure, and academic publications from Carnegie Mellon University CERT/CC. Standards bodies and guidance from NIST, ENISA, ISACA, and SANS Institute have incorporated lessons from attributed incidents. Conferences such as Black Hat, DEF CON, RSA Conference, and workshops at USENIX have featured presentations on tactics, indicators, and mitigations. Collaborative efforts across industry sharing platforms like Information Sharing and Analysis Centers and public-private partnerships have been informed by these reports.

Controversies and Denials

Chinese government statements from the Ministry of National Defense of the People's Republic of China and the Ministry of Foreign Affairs of the People's Republic of China have denied allegations, framing discussions within diplomatic contexts that involve US–China relations, Sino-American dialogues, and cybersecurity confidence-building measures under the Shanghai Cooperation Organisation. Academic critiques from scholars at Harvard Kennedy School and London School of Economics have debated evidentiary standards used in attribution. Journalistic investigations in The New York Times, Foreign Policy, The Washington Post, and The Guardian have contrasted private-sector claims with Chinese denials, while legal scholars at Columbia Law School and Yale Law School have explored implications for international law, sovereignty, and norms in cyberspace.

Category:Cyber espionage