APT40 is a threat actor attributed to China, assessed as espionage-motivated. Its recorded targeting runs to government, private sector across 13 countries in the open reporting we hold — Saudi Arabia among them.
Across 50 attributed ATT&CK techniques we resolve 14 distinct behaviours — the things they do that a detection can be written against. The two that account for most of their observed tradecraft are valid account abuse or account creation and persistence pointing into world-writable staging. Their toolkit is 17 named items: 6 we see only in this actor's reporting and 11 commodity or dual-use. That ratio is the point — the first group is what identifies them, the second is what they share with every other group and with red teams.
For a Gulf defender the relevant line is the victimology: Saudi Arabia appear in the reporting behind this record. That is evidence of past targeting, not a forecast, and it is drawn from what vendors chose to publish — an actor working quietly in a market nobody reports on looks identical to one that is absent.
As MITRE describes them: “Leviathan is an espionage actor targeting organizations and high-value targets in defense and government. Active since at least 2014, this actor has long-standing interest in maritime industries, naval defense contractors, and associated research institutions in the United States and Western Europe.” — MITRE ATT&CK, CC BY 4.0.
On the name. “APT40” labels a cluster of related activity tracked under one name — not a verified organisation. Whether one team, several contractors or a rotating cast sits behind it is not something this record establishes, and the vendor names below are separate groupings that only mostly overlap.