THREATOPS Actor Dossier
LIVE ← Dashboard

APT3

G00222 reports
aliases · APT3 · Gothic Panda · Pirpi · UPS Team · Buckeye · Threat Group-0110 · TG-0110
Export dossier:
2
Reports
11
Techniques
7
Tactics
3
Countries
55%
Hunt coverage
7
Aliases

Analyst assessment — key judgments

  • Signature techniques: T1588.006 (Vulnerabilities), T1059.001 (PowerShell), T1589.001 (Credentials).
  • Primary targeting: RU, US, BR.
  • Resurgent after a quiet period: 1 report(s) in last 30d vs 0 prior (+100%).
  • Recent movement: 6 new technique(s), 17 new infrastructure indicator(s) in the last 30 days.
  • Hunt coverage 55% of 11 observed techniques (5 gap(s)).
  • Assessment confidence: medium (60).

Activity & trend

ResurgentLast 30d: 1 vs 0 prior (+100%)· first reported 2026-07-03 · last 2026-09-16
1
7d
1
30d
2
90d
2
All
0.2
Rpts/wk
Reporting timeline · 12 months

Movement — last 30 days

New techniques
T1590.005T1087.001T1136.001T1583.006T1584.006T1078.002
Targeting gained
RUUS
New infrastructure
1dcafb7f8448683281106b06dd22409a1f3034b706c78b35d8e34044e68c693a3ecd1cd627d0340c92901a478a7caad8631fb131a56caf4ca0f287ed73e876ab4aa9fb1bf9223dfcdac920759bc7a3c7https://www.kaspersky.com/enterprise-sechttps://www.kaspersky.com/enterprise-sechttps://tip.kaspersky.com/landscape/hunthttps://tip.kaspersky.com/landscape/hunthttps://tip.kaspersky.com/landscape/hunthttps://tip.kaspersky.com/landscape/hunthttps://tip.kaspersky.com/landscape/hunt

Vulnerabilities in this actor's reporting · 2

Overview

Analyst triage
Intelligence summary

APT3 is a China-based threat group that researchers have attributed to China's Ministry of State Security.(Citation: FireEye Clandestine Wolf)(Citation: Recorded Future APT3 May 2017) This group is responsible for the campaigns known as Operation Clandestine Fox, Operation Clandestine Wolf, and Operation Double Tap.(Citation: FireEye Clandestine Wolf)(Citation: FireEye Operation Double Tap) As of June 2015, the group appears to have shifted from targeting primarily US victims to primarily political organizations in Hong Kong.(Citation: Symantec Buckeye)

Top co-occurring indicators
    Aliases & naming
      Targeting · countries
        Targeting · named victims

          ATT&CK technique matrix

          Coverage vs hunt library:
          Hunt-coverage gaps — prioritized

            Top techniques by observation

            Threat catalogue · engineering roadmap0

            Flagged detection-engineering queue

            Uncovered techniques you flagged for hunt / detection build-out, aggregated across every actor you visit. Stored locally in your browser.

              No techniques queued yet — flag a gap above to add it here.

              Infrastructure

              IOC type mix
              Tooling / malware families
                Tracked infrastructure

                Relationships

                Related actors (behavioral cluster)
                  Attributed malware
                  Campaigns
                  No behavioral cluster, attributed malware, or campaigns recorded for this actor yet.

                  Activity

                  30-day mention timeline
                  Recent reporting
                  TitleSourceSeverityCollected