APT3
APT3 is a China-linked threat actor also referred to in the provided content as Buckeye, Gothic Panda, UPS Team, TG-0110/Threat Group-0110, Boron, Brocade Typhoon, Cybran, OldCarp, Red Sylvan, and Pirpi. The content describes the group as active since at least 2010 and notes reporting that linked GOTHIC PANDA/APT3 to the Chinese firm Boyusec and ultimately to Ministry of State Security (MSS) entities in Guangzhou. Symantec reporting cited in the content identifies Buckeye/APT3/Gothic Panda/UPS Team/TG-0110 as the actor that used a variant of the NSA-developed DoublePulsar backdoor and a related Windows exploit against multiple targets beginning in March 2016. The group’s observed tradecraft in the provided content includes staging files for exfiltration in a single location; using a downloader that establishes SOCKS5 connections for initial command and control; creating persistence via Startup folder scripts and a scheduled task (for example, schtasks /create /tn "mysc" /tr C:\Users\Public\test.exe /sc ONLOGON /ru "System"); identifying Microsoft Office documents on victim systems; executing cmd.exe /C whoami to verify context; using tools to execute commands on remote computers; listing running processes; deleting files; obtaining local system information; exfiltrating data over the C2 channel; obfuscating files or information to evade defenses; dumping passwords from browsers; locating credentials in files on disk including Firefox or Chrome-related files; injecting into lsass.exe to dump credentials; enabling RDP for persistence; and using RDP sessions to browse and copy files on compromised systems.
Know when an actor pivots toward your sector
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Tradecraft
53 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
Associated malware families
10 malware families attributed to this actor across reporting.
5 additional families tracked in Mallory.
Associated vulnerabilities
3 CVEs this actor has used in observed campaigns. 3 of them exploited in the wild.
APT3 has exploited... Internet Explorer vulnerability CVE-2014-1776.
APT3 has exploited the Adobe Flash Player vulnerability CVE-2015-3113...
This detection identifies instances where Windows Explorer.exe spawns PowerShell or cmd.exe processes, particularly focusing on executions initiated by LNK files. This behavior is associated with the ZDI-CAN-25373 Windows shortcut zero-day vulnerability, where specially crafted LNK files are used to trigger malicious code execution through cmd.exe or powershell.exe. This technique has been actively exploited by multiple APT groups in targeted attacks through both HTTP and SMB delivery methods.
Observables
41 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
Recent activity
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Uses credential dumping by injecting tooling into LSASS to extract credentials.
Listed as a threat actor associated with the PowerShell P/Invoke process injection API chain detection and related ATT&CK techniques.
Listed as a threat actor associated with PowerShell execution behavior relevant to this detection analytic.
Listed as a threat actor associated with use of Cobalt Strike PowerShell loader patterns.
The version that knows your environment.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.