Loading the current evidence view. Navigation and account controls remain available.
Threat actors
Loading the current evidence view. Navigation and account controls remain available.
Also known as: Gothic Panda, Pirpi, UPS Team, Buckeye, Threat Group-0110, TG-0110
44
techniques
6
software
11,416
corpus matches
profile
APT3 is a China-based threat group that researchers have attributed to China's Ministry of State Security. This group is responsible for the campaigns known as Operation Clandestine Fox, Operation Clandestine Wolf, and Operation Double Tap. As of June 2015, the group appears to have shifted from targeting primarily US victims to primarily political organizations in Hong Kong.
techniques
44 attributed · most-instrumented first
software
6 malware & tools attributed
PlugX
S0013
SHOTPUT
S0063
schtasks
S0111
OSInfo
S0165
RemoteCMD
S0166
LaZagne
S0349
read this carefully
11,416 corpus matches is not attribution
That count is indicators which exhibit techniques APT3 is known to use. Many unrelated operators use the same techniques. Treat it as a shared-technique signal for hunting, never as first-party attribution to this group.
indicators exhibiting these techniques
Top by severity: each resolves to its own verdict.
+32 more techniques
showing 30 of 11,416
known aliases
Vendors name the same group differently. Searching any alias reaches this profile.