APT3 — APT Profile
APT3 is a China-based threat group that researchers have attributed to China's Ministry of State Security. This group is responsible for the campaigns known as Operation Clandestine Fox, Operation Clandestine Wolf, and Operation Double Tap. As of June 2015, the group appears to have shifted from targeting primarily US victims to primarily political organizations in Hong Kong.Description reproduced from MITRE ATT&CK. © The MITRE Corporation, reproduced and distributed with permission.
Also tracked as
Gothic Panda, Pirpi, UPS Team, Buckeye, Threat Group-0110, TG-0110, Boyusec, BORON, BRONZE MAYFAIR, Red Sylvan, Brocade Typhoon
IntelFusions coverage (2)
- The Story of Jian: How APT31 Stole and Repurposed an NSA Zero-Day Two Years Before the Shadow Brokers Leak 2026-02-16 · Nation-State
- FireEye Exposes APT3's Operation Clandestine Wolf Exploiting Adobe Flash Zero-Day CVE-2015-3113 2026-02-16 · Nation-State
Tools & malware
- LaZagne Credential Harvesting
- OSInfo Discovery
- PlugX Backdoor
- RemoteCMD Remote Execution
- schtasks Persistence
- SHOTPUT Backdoor
- win.doublepulsar Backdoor
- win.htran Tunneling Tool
- win.keylogger_apt3 Infostealer
- win.pirpi Backdoor
- win.plugx Backdoor
- win.shareip Backdoor
- win.w32times Backdoor
- win.xserver Backdoor
Vendor research
- Operation Clandestine Wolf – Adobe Flash Zero-Day in APT3 Phishing Campaign Eng, E., Caselden, D.
- Operation Double Tap Moran, N., et al
- Buckeye cyberespionage group shifts gaze from US to Hong Kong Symantec Security Response
- Operation Double Tap FireEye
- Recorded Future Research Concludes Chinese Ministry of State Security Behind APT3 Recorded Future
- Operation Clandestine Wolf – Adobe Flash Zero-Day in APT3 Phishing Campaign FireEye
- A tale of Pirpi, Scanbox & CVE-2015-3113 PWC
- Buckeye cyberespionage group shifts gaze from US to Hong Kong Symantec
Countries linked to this actor
- Hong Kong targets