APT3
Also reported as TG-0110, Buckeye, Red Sylvan, Brocade Typhoon, Group 6 and 14 other names. Linked to China by four sources.
Reports per quarter
Techniques seen in the last two years
- T1027 2 reports in ATT&CK
- T1036.005 2 reports reports only
- T1059.001 2 reports in ATT&CK
- T1082 2 reports in ATT&CK
- T1132.001 2 reports reports only
- T1140 2 reports reports only
- T1204.002 2 reports reports only
- T1547.001 2 reports in ATT&CK
- T1566.001 2 reports reports only
- T1573.001 2 reports reports only
Show all 38 techniques Show fewer
- T1001.003 1 report reports only
- T1012 1 report reports only
- T1027.009 1 report reports only
- T1036.007 1 report reports only
- T1041 1 report in ATT&CK
- T1055 1 report reports only
- T1055.012 1 report reports only
- T1057 1 report in ATT&CK
- T1071.001 1 report reports only
- T1083 1 report in ATT&CK
- T1102 1 report reports only
- T1105 1 report in ATT&CK
- T1106 1 report reports only
- T1129 1 report reports only
- T1189 1 report reports only
- T1218 1 report reports only
- T1218.007 1 report reports only
- T1218.014 1 report reports only
- T1497.001 1 report reports only
- T1553.002 1 report reports only
- T1566.002 1 report in ATT&CK
- T1574 1 report reports only
- T1574.001 1 report in ATT&CK
- T1583.001 1 report reports only
- T1583.003 1 report reports only
- T1587.001 1 report reports only
- T1608.001 1 report reports only
- T1627.001 1 report reports only
Counts come from technique IDs in the actor's report text. “Reports only” means reports name the technique but MITRE ATT&CK® does not list it for this actor.
Also listed by ATT&CK
CVEs named in reports
- CVE-2008-3431 KEV
- CVE-2010-1424
- CVE-2010-2152
- CVE-2010-3915
- CVE-2010-3916
- CVE-2010-3962 KEV
- CVE-2011-0611 KEV
- CVE-2011-1331
- CVE-2011-2462 KEV
- CVE-2011-3402 KEV
- CVE-2011-3544 KEV
- CVE-2012-0158 KEV ransomware
Show all 146 CVEs Show fewer
- CVE-2012-1856 KEV
- CVE-2012-1889 KEV
- CVE-2012-4792 KEV
- CVE-2012-5687
- CVE-2013-0707
- CVE-2013-1331 KEV
- CVE-2013-3128
- CVE-2013-3644
- CVE-2013-3893 KEV
- CVE-2013-3894
- CVE-2013-3900 KEV
- CVE-2013-3918 KEV
- CVE-2013-5947
- CVE-2013-5990
- CVE-2014-0160 KEV
- CVE-2014-0322 KEV
- CVE-2014-0810
- CVE-2014-1225
- CVE-2014-1761 KEV
- CVE-2014-1776 KEV
- CVE-2014-2962
- CVE-2014-3393
- CVE-2014-4019
- CVE-2014-4113 KEV
- CVE-2014-4114 KEV
- CVE-2014-6271 KEV
- CVE-2014-6277
- CVE-2014-6278 KEV
- CVE-2014-6332 KEV
- CVE-2014-7169 KEV
- CVE-2014-7186
- CVE-2014-7187
- CVE-2014-7247
- CVE-2014-8361 KEV
- CVE-2014-9583
- CVE-2015-0554
- CVE-2015-1641 KEV
- CVE-2015-1701 KEV ransomware
- CVE-2015-2424 KEV
- CVE-2015-2545 KEV
- CVE-2015-2590 KEV
- CVE-2015-3043 KEV
- CVE-2015-3113 KEV
- CVE-2015-5119 KEV
- CVE-2015-5122 KEV
- CVE-2015-7248
- CVE-2015-7254
- CVE-2015-7645 KEV ransomware
- CVE-2016-5195 KEV
- CVE-2016-7836 KEV
- CVE-2017-0005 KEV
- CVE-2017-0143 KEV ransomware
- CVE-2017-0144 KEV ransomware
- CVE-2017-0199 KEV ransomware
- CVE-2017-0213 KEV ransomware
- CVE-2017-0261 KEV
- CVE-2017-0262 KEV
- CVE-2017-11292 KEV
- CVE-2017-1182
- CVE-2017-11882 KEV ransomware
- CVE-2017-15944 KEV
- CVE-2017-6327 KEV
- CVE-2017-6328
- CVE-2017-7269 KEV
- CVE-2017-8759 KEV
- CVE-2018-0798 KEV
- CVE-2018-0802 KEV ransomware
- CVE-2018-1207
- CVE-2018-13379 KEV ransomware
- CVE-2019-0604 KEV ransomware
- CVE-2019-0703 KEV
- CVE-2019-0708 KEV ransomware
- CVE-2019-0803 KEV ransomware
- CVE-2019-10149 KEV
- CVE-2019-11510 KEV ransomware
- CVE-2019-11580 KEV ransomware
- CVE-2019-16098
- CVE-2019-16920 KEV
- CVE-2019-17100
- CVE-2019-19781 KEV ransomware
- CVE-2019-3369
- CVE-2019-3396 KEV ransomware
- CVE-2019-9489
- CVE-2020-0601 KEV
- CVE-2020-0688 KEV ransomware
- CVE-2020-0796 KEV ransomware
- CVE-2020-0986 KEV
- CVE-2020-10189 KEV
- CVE-2020-1040 KEV
- CVE-2020-1350 KEV
- CVE-2020-1380 KEV
- CVE-2020-1472 KEV ransomware
- CVE-2020-1664
- CVE-2020-2021 KEV ransomware
- CVE-2020-5135 KEV ransomware
- CVE-2020-5902 KEV ransomware
- CVE-2020-6789
- CVE-2020-8468 KEV
- CVE-2020-8515 KEV
- CVE-2021-1675 KEV ransomware
- CVE-2021-22555 KEV
- CVE-2021-26855 KEV ransomware
- CVE-2021-26857 KEV ransomware
- CVE-2021-26858 KEV ransomware
- CVE-2021-27065 KEV ransomware
- CVE-2021-31195
- CVE-2021-31196 KEV
- CVE-2021-31206
- CVE-2021-31207 KEV ransomware
- CVE-2021-34473 KEV ransomware
- CVE-2021-34523 KEV ransomware
- CVE-2021-34527 KEV ransomware
- CVE-2021-4034 KEV ransomware
- CVE-2021-40444 KEV ransomware
- CVE-2021-4104
- CVE-2021-44207 KEV
- CVE-2021-44228 KEV ransomware
- CVE-2021-45046 KEV ransomware
- CVE-2021-45105
- CVE-2022-21587 KEV ransomware
- CVE-2022-24682 KEV ransomware
- CVE-2022-24934
- CVE-2022-27924 KEV ransomware
- CVE-2022-27925 KEV ransomware
- CVE-2022-30333 KEV ransomware
- CVE-2022-37042 KEV ransomware
- CVE-2022-41040 KEV ransomware
- CVE-2022-41082 KEV ransomware
- CVE-2022-41328 KEV
- CVE-2022-42475 KEV ransomware
- CVE-2022-47986 KEV ransomware
- CVE-2022-49475
- CVE-2024-0012 KEV ransomware
- CVE-2024-24919 KEV ransomware
KEV marks a CVE in CISA's Known Exploited Vulnerabilities Catalog, and “ransomware” marks one that the catalog records as used in ransomware campaigns.
Reports
-
Threat Group Cards: A Threat Actor Encyclopedia
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Threat Group Cards: A Threat Actor Encyclopedia
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor APT 3, Gothic Panda, Buckeye
Show all 246 reports Show fewer
-
ICIT Brief – China’s Espionage Dynasty: Economic Death by a Thousand Cuts
The title opens Wayback Machine, not the publisher’s page. Archived copy on ORKL Detailsfor ICIT Brief – China’s Espionage Dynasty: Economic Death by a Thousand Cuts
-
Wirtschaftsspionage gegen Volkwagen: VW-Konzern wurde jahrelang ausge…
The title opens archive.today, not the publisher’s page. Archived copy on ORKL Detailsfor Wirtschaftsspionage gegen Volkwagen: VW-Konzern wurde jahrelang ausge…
-
PlugX Malware Being Distributed via Vulnerability Exploitation
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor PlugX Malware Being Distributed via Vulnerability Exploitation
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Demonstrating_Hustle
-
MustangPanda%20-%20Enemy%20at%20the%20gate_final.pdf
The original link failed its last check. Original publisher Detailsfor MustangPanda%20-%20Enemy%20at%20the%20gate_final.pdf
-
Rising Tide- Chasing the Currents of Espionage in the South China Sea
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Rising Tide- Chasing the Currents of Espionage in the South China Sea
-
yir-cyber-threats-annex-download.pdf
The original link failed its last check. Original publisher Detailsfor yir-cyber-threats-annex-download.pdf
-
Unmasking China’s State Hackers
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Unmasking China’s State Hackers
-
Chinese Influence Operations A Machiavellian Moment
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Chinese Influence Operations A Machiavellian Moment
-
Mustang Panda PlugX - 45.251.240.55 Pivot
The original link failed its last check. Original publisher Detailsfor Mustang Panda PlugX - 45.251.240.55 Pivot
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Who is Mr. Zhao-
-
CSET - Academics, AI, and APTs
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor CSET - Academics, AI, and APTs
-
research.checkpoint.com-The Story of Jian How APT31 Stole and Used an Unknown Equation Group 0-Day
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor research.checkpoint.com-The Story of Jian How APT31 Stole and Used an Unknown Equation Group 0-Day
-
The Story of Jian – How APT31 Stole and Used an Unknown Equation Group 0-Day
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor The Story of Jian – How APT31 Stole and Used an Unknown Equation Group 0-Day
-
Higaisa or Winnti? APT41 backdoors, old and new
The original link failed its last check. Original publisher Detailsfor Higaisa or Winnti? APT41 backdoors, old and new
-
OceanLotus Continues With Its Cyber Espionage Operations
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor OceanLotus Continues With Its Cyber Espionage Operations
-
Alert (AA20-275A)- Potential for China Cyber Response to Heightened U.S.-China Tensions
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Alert (AA20-275A)- Potential for China Cyber Response to Heightened U.S.-China Tensions
-
Is APT 27 Abusing COVID-19 To Attack People !
The original link failed its last check. Detailsfor Is APT 27 Abusing COVID-19 To Attack People !
-
APT40 is run by the Hainan department of the Chinese Ministry of State Security
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor APT40 is run by the Hainan department of the Chinese Ministry of State Security
-
Reviving MuddyC3 Used by MuddyWater (IRAN) APT
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Reviving MuddyC3 Used by MuddyWater (IRAN) APT
-
What is the Hainan Xiandun Technology Development Company-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor What is the Hainan Xiandun Technology Development Company-
-
cds19-executive-s08-achievement-unlocked.pdf
The original link failed its last check. Original publisher Detailsfor cds19-executive-s08-achievement-unlocked.pdf
-
The original link failed its last check. Original publisher Detailsfor Analytics
-
BLOG SERIES_Huge Fan of Your Work
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor BLOG SERIES_Huge Fan of Your Work
-
The link to Mirror on Box failed its last check. Mirror on Box Detailsfor Two Birds, One STONE PANDA
-
UPSynergy_ Chinese-American Spy vs. Spy Story
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor UPSynergy_ Chinese-American Spy vs. Spy Story
-
APT41: A Dual Espionage and Cyber Crime Operation
The link to Mirror on Box failed its last check. Mirror on Box Detailsfor APT41: A Dual Espionage and Cyber Crime Operation
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor report_APT41
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Is there a pattern-
-
Into the Fog - The Return of ICEFOG APT
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Into the Fog - The Return of ICEFOG APT
-
Buckeye- Espionage Outfit Used Equation Group Tools Prior to Shadow Brokers Leak
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Buckeye- Espionage Outfit Used Equation Group Tools Prior to Shadow Brokers Leak
-
Buckeye_ Espionage Outfit Used Equation Group Tools Prior to Shadow Brokers Leak
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Buckeye_ Espionage Outfit Used Equation Group Tools Prior to Shadow Brokers Leak
-
APT10 Targeted Norwegian MSP and US Companies in Sustained Campaign
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor APT10 Targeted Norwegian MSP and US Companies in Sustained Campaign
-
APT10 Targeted Norwegian MSP and US Companies in Sustained Campaign
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor APT10 Targeted Norwegian MSP and US Companies in Sustained Campaign
-
VB2018 - Who Was Not Responsible for Olympic Destroyer
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor VB2018 - Who Was Not Responsible for Olympic Destroyer
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Two Birds, One STONE PANDA
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Two Birds, One STONE PANDA
-
APT10 was managed by the Tianjin bureau of the Chinese Ministry of State Security
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor APT10 was managed by the Tianjin bureau of the Chinese Ministry of State Security
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor More on Huaying Haitai and Laoying Baichaun, the companies associated with APT10. Is there a state connection-
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor The destruction of APT3
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor The destruction of APT3
-
Who Wasn’t Responsible for Olympic Destroyer-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Who Wasn’t Responsible for Olympic Destroyer-
-
techdoc_lite-deliverables-numbered option.dotx
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor techdoc_lite-deliverables-numbered option.dotx
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Intro
-
Recorded Future Research Concludes Chinese Ministry of State Security Behind APT3
The link to Mirror on Box failed its last check. Mirror on Box Detailsfor Recorded Future Research Concludes Chinese Ministry of State Security Behind APT3
-
APT3 is Boyusec, a Chinese Intelligence Contractor
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor APT3 is Boyusec, a Chinese Intelligence Contractor
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Who is Mr Dong-
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Who is Mr Wu-
-
Who is behind this Chinese espionage group stealing our intellectual property-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Who is behind this Chinese espionage group stealing our intellectual property-
-
Buckeye cyberespionage group shifts gaze from US to Hong Kong
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Buckeye cyberespionage group shifts gaze from US to Hong Kong
-
Buckeye cyberespionage group shifts gaze from US to Hong Kong
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Buckeye cyberespionage group shifts gaze from US to Hong Kong
-
Buckeye cyberespionage group shifts gaze from US to Hong Kong
The title opens Wayback Machine, not the publisher’s page. Archived copy on ORKL Detailsfor Buckeye cyberespionage group shifts gaze from US to Hong Kong
-
ICIT-Brief-China-Espionage-Dynasty
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor ICIT-Brief-China-Espionage-Dynasty
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Please Read
-
The original link failed its last check. Original publisher Detailsfor security_report_20160613.pdf
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Ghosts in the Endpoint
-
The original link failed its last check. Original publisher Detailsfor rpt-mtrends-2016.pdf
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor rpt-witchcoven
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor HTExploitTelemetry
-
Uncovering the Seven Pointed Dagger
The link to Mirror on Box failed its last check. Mirror on Box Detailsfor Uncovering the Seven Pointed Dagger
-
UPS- Observations on CVE-2015-3113, Prior Zero-Days and the Pirpi Payload
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor UPS- Observations on CVE-2015-3113, Prior Zero-Days and the Pirpi Payload
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor APT Group UPS Targets US Government with Hacking Team Flash Exploit - Palo Alto Networks BlogPalo Alto Networks Blog
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Operation Clandestine Wolf
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Operation Clandestine Wolf
-
Operation Clandestine Wolf – Adobe Flash Zero-Day in APT3 Phishing Campaign
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Operation Clandestine Wolf – Adobe Flash Zero-Day in APT3 Phishing Campaign
-
The original link failed its last check. Original publisher Detailsfor rpt-m-trends-2015.pdf
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Global Threat Intel Report
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Operation Double Tap
-
Operation Double Tap « Threat Research | FireEye Inc
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Operation Double Tap « Threat Research | FireEye Inc
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor New Zero-Day Exploit targeting Internet Explorer Versions 9 through 11 Identified in Targeted Attacks
-
APT34 Deploys Phishing Attack With New Malware
The original link failed its last check. Original publisher Detailsfor APT34 Deploys Phishing Attack With New Malware
-
BKDR_RARSTONE: New RAT to Watch Out For - TrendLabs Security Intelligence Blog
The title opens Wayback Machine, not the publisher’s page. Archived copy on ORKL Detailsfor BKDR_RARSTONE: New RAT to Watch Out For - TrendLabs Security Intelligence Blog
Newest first. Details opens the report in Explore.