Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started

Also known as: Gothic Panda, Pirpi, UPS Team, Buckeye, Threat Group-0110, TG-0110, APT3, Group 6, Boyusec – the Guangzhou Boyu Information Technology Company, Ltd, UPS, Boyusec, BORON, BRONZE MAYFAIR, Red Sylvan, Brocade Typhoon

Description

APT3 is a China-based threat group that researchers have attributed to China's Ministry of State Security.(Citation: FireEye Clandestine Wolf)(Citation: Recorded Future APT3 May 2017) This group is responsible for the campaigns known as Operation Clandestine Fox, Operation Clandestine Wolf, and Operation Double Tap.(Citation: FireEye Clandestine Wolf)(Citation: FireEye Operation Double Tap) As of June 2015, the group appears to have shifted from targeting primarily US victims to primarily political organizations in Hong Kong.(Citation: Symantec Buckeye)

TTP Summary

Clandestine Fox; Double Tap; Clandestine Wolf DLL Side-Loading: Chrome.exe → chrome_frame_helper.dll (Google)

Goals & Targeting

Targeted Sectors

Defense
Energy
Technology
Telecommunications
Aerospace & defense
Transportation
Ngo

Targeted Countries / Regions

US
GB

AI Analysis

· 1 week ago

Executive Summary

APT3, also known as Gothic Panda or Pirpi, is a Chinese state-sponsored cyber threat group linked to espionage activities targeting defense, energy, technology, and other sectors in the US and UK. The group employs sophisticated tactics including DLL side-loading and credential harvesting to achieve long-term access and data exfiltration.

Goals & Targeting

APT3's primary motivation is espionage, seeking sensitive information from defense contractors, energy companies, and technology firms to support national security interests in China. The group primarily targets the US and UK, focusing on sectors that provide strategic value such as aerospace, telecommunications, and defense. Victims include government agencies, NGOs operated within China or by Chinese stakeholders, and think tanks associated with Chinese policy matters.

Enhanced Description

APT3 is a China-based advanced persistent threat (APT) group widely believed to be associated with the Chinese Ministry of State Security. Known for its involvement in operations such as Clandestine Wolf, Double Tap, and Clandestine Fox, APT3 has demonstrated a focus on long-term, stealthy espionage campaigns. The group typically targets government ministries, NGOs, and think tanks in the United States and other regions. APT3's tactics include DLL side-loading for persistence and lateral movement within networks using tools like PlugX and SHOTPUT. Their activities have evolved over time, shifting from initial focus on US entities to later operations targeting political organizations in Hong Kong.

Key Capabilities

  • DLL side-loading for persistence
  • Credential harvesting via custom malware (e.g., PlugX)
  • Remote command and control using RemoteCMD
  • Information collection and exfiltration through staged infrastructure
  • Lateral movement within compromised networks

MITRE ATT&CK Tactics

Collection
Credential Access
Exfiltration
Defense Evasion
Discovery

ATT&CK Techniques

T1053.005: Scheduled Task
T1560.001: Archive via Utility
T1059.003: Windows Command Shell
T1041: Exfiltration Over C2 Channel
T1485.004: Web Shell for Lateral Movement

Software / Tooling

PlugX
SHOTPUT
RemoteCMD
Cobalt Strike-like frameworks (potential)

Campaigns & Victims

APT3 has been involved in multiple high-profile campaigns targeting government and private sector entities. These campaigns often involve initial compromise via phishing or supply chain attacks, followed by stealthy data gathering over extended periods. Notable operations include Clandestine Wolf, where APT3 targeted US defense contractors, and Double Tap, which focused on Hong Kong-based political organizations. The group’s operational tempo appears to align with strategic geopolitical interests, often pausing activity during sensitive diplomatic events.

IOC Patterns

  • DLL side-loading via legitimate executables (e.g., Chrome.exe)
  • Scheduled tasks created for persistence
  • Staged exfiltration via web-based command and control (C2)
  • Presence of custom malware components in network traffic
  • Abnormal process activity linked to known APT3 tools

Recommended Actions

  • Monitor for scheduled tasks and unusual process activity on endpoints.
  • Implement strong email filtering to detect and block phishing attempts.
  • Use endpoint detection and response (EDR) solutions to identify malicious processes like those related to PlugX or SHOTPUT.
  • Conduct regular system updates and patch management to mitigate known vulnerabilities exploited by APT actors.
  • Limit user privileges and adopt least-privilege principles to reduce lateral movement opportunities.

Suggested Tags

APT
espionage
defense sector
US-targeted attacks
China-linked

Confidence Assessment

High confidence in APT3's state sponsorship by China and its focus on espionage activities. However, gaps exist in understanding the full scope of its operations post-2015, particularly regarding targeting shifts and specific campaign tactics beyond known TTPs.

ATT&CK Techniques

Discovery
9 techniques
Execution
5 techniques
Stealth
9 techniques

Observed Data

No observed data linked yet.

Indicators of Compromise

Domain 9 URL 2 IPv4 Address 8 IPV4 1

References

  1. FireEye Clandestine Wolf — Eng, E., Caselden, D.. (2015, June 23). Operation Clandestine Wolf – Adobe Flash Zero-Day in APT3 Phishing Campaign. Retrieved January 14, 2016.
  2. Recorded Future APT3 May 2017 — Insikt Group (Recorded Future). (2017, May 17). Recorded Future Research Concludes Chinese Ministry of State Security Behind APT3. Retrieved September 16, 2024.
  3. PWC Pirpi Scanbox — Lancaster, T. (2015, July 25). A tale of Pirpi, Scanbox & CVE-2015-3113. Retrieved March 30, 2016.
  4. FireEye Operation Double Tap — Moran, N., et al. (2014, November 21). Operation Double Tap. Retrieved January 14, 2016.
  5. Symantec Buckeye — Symantec Security Response. (2016, September 6). Buckeye cyberespionage group shifts gaze from US to Hong Kong. Retrieved September 26, 2016.

Intel Summary

45

Techniques

16

Tools

3

Campaigns

67

IOCs

0

Observed Data

12

Tactics

Tags

APT
Government Targeting
espionage
defense sector
US-targeted attacks
China-linked

Details

MITRE ID
G0022
Type
Unknown
Resource Level
Government
Primary Motivation
Espionage
Country of Origin
China (CN)
Confidence
90%
Added
May 2, 2026
STIX ID
intrusion-set--0bbdf25b-30ff-4894-a1cd-49260d0dd2d9
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.