TEMP.Jumper

Threat Actor Profile Updated 5 days ago
Download STIX
Preview STIX
TEMP.Jumper, also known as TEMP.Periscope, Leviathan, APT40, and several other aliases, is a China-nexus cyber espionage group. This threat actor has been active in the cybersecurity landscape for years, targeting government organizations, private businesses, and universities worldwide. Notably, between 2011 and 2018, the group carried out numerous hacking operations, leading to the U.S. Justice Department indicting four of its members in July 2021. The group's activities have drawn international attention, with cybersecurity agencies from Australia, Canada, Germany, Japan, New Zealand, South Korea, the UK, and the US issuing a joint advisory warning about APT40. The warning highlighted the group's capability to rapidly exploit disclosed flaws, indicating a high level of sophistication and agility in their operations. This aligns with the observed tactics, techniques, and procedures (TTPs) of TEMP.Jumper, which overlap significantly with those of TEMP.Periscope and public reporting on "NanHaiShu." In terms of malware usage, TEMP.Periscope has leveraged a relatively large library of tools shared with multiple other suspected Chinese groups. One such tool is AIRBREAK, a JavaScript-based backdoor also reported as "Orz" that retrieves commands from hidden strings in compromised webpages and actor-controlled profiles on legitimate services. This suggests an advanced operational capacity and underscores the necessity for robust cybersecurity measures to mitigate threats posed by this group.
What's your take? (Question 1 of 5)
Help tune the shared Cybergeist dataset, assist your peers, and earn karma. Expand the panel to get started.
Possible Aliases / Cluster overlaps
It's hard to track cluster overlaps and naming conventions between vendors, so here are some possible overlapping names / profiles you also may want to look at.
IDVotesProfile Description
TEMP.Periscope
2
TEMP.Periscope, also known as APT40 and TEMP.Jumper among other names, is a threat actor group with a nexus to China that has been active since at least 2013. This group is known for its cyber espionage activities primarily targeting maritime-related entities across various sectors such as engineeri
NanHaiShu
1
None
APT40
1
APT40, also known as Red Ladon or IslandDreams, is a Chinese cyber espionage group suspected of being linked to the People's Republic of China (PRC). The group typically targets sectors strategically important to China's Belt and Road Initiative, using at least 51 different code families for its ope
Leviathan
1
Leviathan is a threat actor group that has been linked to various Advanced Persistent Threat (APT) groups such as APT40, also known as Kryptonite Panda, Gingham Typhoon, and Bronze Mohawk. These groups have been reported to be state-sponsored by the People's Republic of China (PRC). Leviathan has re
Miscellaneous Associations
Other elements of context that could aid in the identification of relevance
Exploit
China
Malware
Espionage
Backdoor
Associated Malware
To see the evidence that has resulted in this association, create a free account
IDTypeVotesProfile Description
OrzUnspecified
1
Orz is a malicious software (malware) known for its detrimental capabilities to exploit and damage computer systems. It infiltrates systems through suspicious downloads, emails, or websites, often unbeknownst to the user, and can steal personal information, disrupt operations, or hold data hostage f
AirbreakUnspecified
1
Airbreak is a malicious software (malware) used by Advanced Persistent Threat group APT40, known for its sophisticated cyber-espionage campaigns. This JavaScript-based backdoor malware retrieves commands from hidden strings in compromised webpages and actor-controlled profiles on legitimate services
Associated Threat Actors
To see the evidence that has resulted in this association, create a free account
IDTypeVotesProfile Description
No associations to display
Associated Vulnerabilities
To see the evidence that has resulted in this association, create a free account
IDTypeVotesProfile Description
No associations to display
Source Document References
Information about the TEMP.Jumper Threat Actor was read from the documents corpus below. This display is limited to 20 results, create a free account to see more
SourceCreatedAtTitle
Securityaffairs
5 days ago
Cybersecurity agencies warn of China-linked APT40 's capabilities
MITRE
a year ago
Suspected Chinese Cyber Espionage Group (TEMP.Periscope) Targeting U.S. Engineering and Maritime Industries | Mandiant
MITRE
a year ago
APT40: Examining a China-Nexus Espionage Actor | Mandiant