Also known as: Gothic Panda, Pirpi, UPS Team, Buckeye, Threat Group-0110, TG-0110, APT3, Group 6, Boyusec – the Guangzhou Boyu Information Technology Company, Ltd, UPS, Boyusec, BORON, BRONZE MAYFAIR, Red Sylvan, Brocade Typhoon
APT3 is a China-based threat group that researchers have attributed to China's Ministry of State Security.(Citation: FireEye Clandestine Wolf)(Citation: Recorded Future APT3 May 2017) This group is responsible for the campaigns known as Operation Clandestine Fox, Operation Clandestine Wolf, and Operation Double Tap.(Citation: FireEye Clandestine Wolf)(Citation: FireEye Operation Double Tap) As of June 2015, the group appears to have shifted from targeting primarily US victims to primarily political organizations in Hong Kong.(Citation: Symantec Buckeye)
Clandestine Fox; Double Tap; Clandestine Wolf DLL Side-Loading: Chrome.exe → chrome_frame_helper.dll (Google)
Targeted Sectors
Targeted Countries / Regions
Executive Summary
APT3, also known as Gothic Panda or Pirpi, is a Chinese state-sponsored cyber threat group linked to espionage activities targeting defense, energy, technology, and other sectors in the US and UK. The group employs sophisticated tactics including DLL side-loading and credential harvesting to achieve long-term access and data exfiltration.
Goals & Targeting
APT3's primary motivation is espionage, seeking sensitive information from defense contractors, energy companies, and technology firms to support national security interests in China. The group primarily targets the US and UK, focusing on sectors that provide strategic value such as aerospace, telecommunications, and defense. Victims include government agencies, NGOs operated within China or by Chinese stakeholders, and think tanks associated with Chinese policy matters.
Enhanced Description
APT3 is a China-based advanced persistent threat (APT) group widely believed to be associated with the Chinese Ministry of State Security. Known for its involvement in operations such as Clandestine Wolf, Double Tap, and Clandestine Fox, APT3 has demonstrated a focus on long-term, stealthy espionage campaigns. The group typically targets government ministries, NGOs, and think tanks in the United States and other regions. APT3's tactics include DLL side-loading for persistence and lateral movement within networks using tools like PlugX and SHOTPUT. Their activities have evolved over time, shifting from initial focus on US entities to later operations targeting political organizations in Hong Kong.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
APT3 has been involved in multiple high-profile campaigns targeting government and private sector entities. These campaigns often involve initial compromise via phishing or supply chain attacks, followed by stealthy data gathering over extended periods. Notable operations include Clandestine Wolf, where APT3 targeted US defense contractors, and Double Tap, which focused on Hong Kong-based political organizations. The group’s operational tempo appears to align with strategic geopolitical interests, often pausing activity during sensitive diplomatic events.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
High confidence in APT3's state sponsorship by China and its focus on espionage activities. However, gaps exist in understanding the full scope of its operations post-2015, particularly regarding targeting shifts and specific campaign tactics beyond known TTPs.
No observed data linked yet.
45
Techniques
16
Tools
3
Campaigns
67
IOCs
0
Observed Data
12
Tactics