Skip to content
Cyber Science Lab

Advanced Persistent Threat (APT) Malware Dataset

Samples associated with advanced persistent threat campaigns.

Published 2020. Cyber threats are increasingly sophisticated in their tactics, techniques, and procedures (TTP). Attack campaigns can be attributed by analyzing threat actor TTPs, and large-scale malware often mirrors high-risk Advanced Persistent Threat (APT) attacks.

Introduction

Understanding attack origins through machine learning-based cyberthreat attribution can help prevent serious damage. This dataset enables better comprehension of the relationships between APT groups and their TTPs.

Dataset details

The dataset comprises 1,200 APT malware samples across five major APT groups:

  • APT1
  • APT3
  • APT28
  • APT33
  • APT37

Other campaign names, including Winniti, are subcategories of these major campaigns. The samples were executed in a customized Cuckoo Sandbox to collect multiple static and dynamic views, generating four raw views: Header, Opcode, Bytecode, and Systemcall. Cuckoo version 2.0.61 served as the sandbox base for generating dynamic malware views.

Citation

H. Haddadpajouh, A. Azmoodeh, A. Dehghantanha and R. M. Parizi, “MVFCC: A Multi-View Fuzzy Consensus Clustering Model for Malware Threat Attribution,” in IEEE Access, vol. 8, pp. 139188–139198, 2020, doi: 10.1109/ACCESS.2020.3012907.

Download

The dataset is available on GitHub.