Corvus
Evidence · Source Records · Forensic Audit Trail

Evidence

Every claim in this report traces back to one of 31 evidence records below. Each was captured passively during recon, hashed at capture for chain-of-custody, and graded per the Admiralty Scale (NATO STANAG 2511). Click any ev_xxx chip elsewhere in the report to jump straight to its source record.

31
Records
31
Sources
29
High Grade
2
Moderate
0
Low Grade
2026-06-15
Captured
31 of 31 shown
ev_001 A-1
Source Mandiant — APT1: Exposing One of China's Cyber Espionage Units (Feb 2013) · Captured
PLA Unit 61398 is also located in precisely the same area from which APT1 activity appears to originate. … 141 organizations across 20 industries.
SHA-256
ev_002 B-2
Source Wikipedia — PLA Unit 61398 · Captured
PLA Unit 61398 is the military unit cover designator (MUCD) of a People's Liberation Army advanced persistent threat unit … stationed in Pudong, Shanghai … cited by US intelligence agencies since 2002.
SHA-256
ev_003 B-2
Source Wikipedia — Mandiant · Captured
In December 2013, FireEye acquired Mandiant for $1 billion. … In March 2022, Google announced it would acquire Mandiant for $5.4 billion. The firm was fully incorporated into the Google Cloud division in September 2022.
SHA-256
ev_004 B-2
Source Wikipedia — Advanced persistent threat · Captured
An advanced persistent threat (APT) is a stealthy cybersecurity threat, typically manipulated by a state or state-sponsored group …
SHA-256
ev_005 B-2
Source Wikipedia — Chinese intelligence activity abroad · Captured
The government of the People's Republic of China is engaged in espionage overseas, directed through diverse methods via the Ministry of State Security (MSS) … and People's Liberation Army (PLA) via its Intelligence Bureau of the Joint Staff Department …
SHA-256
ev_006 A-1
Source U.S. Department of Justice — Press release: U.S. Charges Five Chinese Military Hackers for Cyber Espionage Against U.S. Corporations and a Labor Organization for Commercial Advantage (May 19, 2014) · Captured
A grand jury in the Western District of Pennsylvania (WDPA) indicted five Chinese military hackers for computer hacking, economic espionage and other offenses … directed at six American victims.
SHA-256
ev_007 A-1
Source U.S. Department of Justice — United States v. Wang Dong et al., grand-jury indictment (W.D. Pa., May 1, 2014) · Captured
Defendants WANG, SUN, and WEN, among others known and unknown to the Grand Jury, hacked …
SHA-256
ev_009 A-2
Source Council on Foreign Relations — Department of Justice Indicts Chinese Hackers: What Next? (May 19, 2014) · Captured
The Department of Justice has indicted five officers in Unit 61398 of the Chinese People's Liberation Army (PLA) — Wang Dong, Sun Kailiang, Wen Xinyu, Huang Zhenyu, and Gu Chunhui.
SHA-256
ev_010 A-2
Source MITRE ATT&CK — APT1 (Group G0006) · Captured
APT1 is a Chinese threat group that has been attributed to the 2nd Bureau of the People's Liberation Army (PLA) General Staff Department's (GSD) 3rd Department.
SHA-256
ev_012 B-2
Source Wikipedia — Salt Typhoon · Captured
He identified the groups Salt Typhoon and Volt Typhoon, which also infiltrated U.S. systems for espionage and potential sabotage …
SHA-256
ev_013 A-1
Source CISA — Cybersecurity Advisory AA25-239A: Countering Chinese State-Sponsored Actors Compromise of Networks Worldwide (Sept 3, 2025) · Captured
People's Republic of China (PRC) state-sponsored cyber threat actors are targeting networks globally …
SHA-256
ev_014 B-2
Source Forbes — Researchers Name Three Hackers Tied To One Of China's Most Active Military Intrusion Teams (Andy Greenberg, Feb 19, 2013) · Captured
… hacker named Wang Dong, a.k.a. Ugly Gorilla. … Mei Qiang (a.k.a. Superhard) … DOTA used some of the same domains and IP addresses for data theft as Wang Dong.
SHA-256
ev_016 A-2
Source Center for Naval Analyses — The Chinese Military's New Information Support Force (Aug 2024) · Captured
A key casualty of the reform was the PLA's Strategic Support Force, which was dissolved in the reorganization despite having been established in late 2015.
SHA-256
ev_018 B-2
Source Wikipedia — Operation Aurora · Captured
Operation Aurora was a series of cyber attacks performed by advanced persistent threats such as the Elderwood Group based in Beijing, China, with associations with the People's Liberation Army.
SHA-256
ev_019 B-2
Source Wikipedia — Titan Rain · Captured
Titan Rain was a series of coordinated attacks on computer systems in the United States since 2003 … attacks originated in Guangdong, China.
SHA-256
ev_020 B-2
Source Wikipedia — Cyberwarfare and China · Captured
Cyberwarfare is the strategic use of computer technology to disrupt the functions of a state or organization …
SHA-256
ev_021 B-2
Source Wikipedia — Wang Dong (hacker) · Captured
Wang Dong … hacker who is part of PLA Unit 61398. Other names: Jack Wang, UglyGorilla, Greenfield.
SHA-256
ev_022 B-2
Source European Repository of Cyber Incidents — APT-1 Profile (Dec 15, 2022) · Captured
Mandiant has traced APT 1 operators to a physical address that overlaps with the compound at which Unit 61398 is stationed in the Pudong New Area …
SHA-256
ev_023 C-3
Source Hedgehog Security — APT1: The Persistent Data Hoarder (threat profile) · Captured
Operating as PLA Unit 61398 from a 12-storey building in Shanghai's Pudong district, the group systematically compromised 141 organisations across 20 industries.
SHA-256
ev_024 A-2
Source National Security Archive, George Washington University — Mandiant APT1 report, archival hosting (Document 83, Cyber Vault) · Captured
The focus of this report is APT 1 — which the report concludes is the People['s] Liberation Army's Unit 61398 — the military unit cover designator.
SHA-256
ev_027 A-2
Source Jamestown Foundation — A Disturbance in the Force: The Reorganization of People's Liberation Army Command and Elimination of China's Strategic Support Force (Apr 26, 2024) · Captured
The April 2024 reorganization eliminated the Strategic Support Force and subordinated the Space Systems Department and Network Systems …
SHA-256
ev_028 A-2
Source Council on Foreign Relations — PLA Unit 61398 (Cyber Operations Tracker) · Captured
The APT 1 report exposed the infrastructure of a cyber threat actor and gave both government and nongovernment organizations insight into the escalating nature …
SHA-256
ev_031 A-2
Source Zetter Zero Day — How the Infamous APT-1 Report Exposing China's PLA Hackers Came to Be (Kim Zetter, Sep 11, 2025) · Captured
Mandiant changed this with its groundbreaking report, which not only tied the activity directly to a specific PLA unit — Unit 61398 — and to … Wang Dong (aka UglyGorilla), Mei Qiang (aka SuperHard) and an individual who used the handle 'DOTA'.
SHA-256