APT3 — APT Profile
APT3 is a China-based threat group that researchers have attributed to China's Ministry of State Security. This group is responsible for the campaigns known as Operation Clandestine Fox, Operation Clandestine Wolf, and Operation Double Tap. As of June 2015, the group appears to have shifted from targeting primarily US victims to primarily political organizations in Hong Kong.Also tracked as
Gothic Panda, Pirpi, UPS Team, Buckeye, Threat Group-0110, TG-0110
Tools & malware
- LaZagne Credential Harvesting
- OSInfo Discovery
- PlugX Backdoor
- RemoteCMD Remote Execution
- schtasks Persistence
- SHOTPUT Backdoor
- win.doublepulsar Backdoor
- win.htran Tunneling Tool
- win.keylogger_apt3 Infostealer
- win.pirpi Backdoor
- win.plugx Backdoor
- win.shareip Backdoor
- win.w32times Backdoor
- win.xserver Backdoor
Vendor research
- dubbed Operation Clandestine Wolf Google Threat Intelligence
- Buckeye cyberespionage group shifts gaze from US to Hong Kong Symantec Security Response
- A tale of Pirpi, Scanbox & CVE-2015-3113 PWC
- Operation Clandestine Wolf – Adobe Flash Zero-Day in APT3 Phishing Campaign FireEye
- Buckeye cyberespionage group shifts gaze from US to Hong Kong Symantec
- Operation Double Tap FireEye
- Recorded Future Research Concludes Chinese Ministry of State Security Behind APT3 Recorded Future