Introduction
APT3 is a China-based threat group that researchers have attributed to Chinaβs Ministry of State Security. FireEye Clandestine Wolf Recorded Future APT3 May 2017 This group is responsible for the campaigns known as Operation Clandestine Fox, Operation Clandestine Wolf, and Operation Double Tap. FireEye Clandestine Wolf FireEye Operation Double Tap As of June 2015, the group appears to have shifted from targeting primarily US victims to primarily political organizations in Hong Kong. Symantec Buckeye
Activities and Tactics
Targeted Sectors: Political party, Private sector
Country of Origin: π¨π³ China
Risk Level: High
First Seen: 2015
Last Activity: 2018
Incident Type: Espionage
Suspected Victims: United States, United Kingdom, Hong Kong
Notable Campaigns
- Clandestine Fox
- Double Tap
- Clandestine Wolf
Tactics, Techniques, and Procedures (TTPs)
- T1053.005 Scheduled Task
- T1104 Multi-Stage Channels
- T1110.002 Password Cracking
- T1564.003 Hidden Window
- T1555.003 Credentials from Web Browsers
- T1059.003 Windows Command Shell
- T1016 System Network Configuration Discovery
- T1049 System Network Connections Discovery
- T1090.002 External Proxy
- T1218.011 Rundll32
- T1027 Obfuscated Files or Information
- T1566.002 Spearphishing Link
- T1098.007 Additional Local or Domain Groups
- T1204.001 Malicious Link
- T1041 Exfiltration Over C2 Channel
- T1552.001 Credentials In Files
- T1074.001 Local Data Staging
- T1078.002 Domain Accounts
- T1005 Data from Local System
- T1203 Exploitation for Client Execution
- T1021.002 SMB/Windows Admin Shares
- T1574.001 DLL
- T1087.001 Local Account
- T1070.004 File Deletion
- T1083 File and Directory Discovery
- T1546.008 Accessibility Features
- T1560.001 Archive via Utility
- T1082 System Information Discovery
- T1059.001 PowerShell
- T1543.003 Windows Service
- T1003.001 LSASS Memory
- T1547.001 Registry Run Keys / Startup Folder
- T1021.001 Remote Desktop Protocol
- T1057 Process Discovery
- T1095 Non-Application Layer Protocol
- T1069 Permission Groups Discovery
- T1018 Remote System Discovery
- T1056.001 Keylogging
- T1036.010 Masquerade Account Name
- T1027.002 Software Packing
- T1136.001 Local Account
- T1105 Ingress Tool Transfer
- T1033 System Owner/User Discovery
- T1027.005 Indicator Removal from Tools
ATT&CK technique IDs (denormalized)
- T1003.001
- T1005
- T1016
- T1018
- T1021.001
- T1021.002
- T1027
- T1027.002
- T1027.005
- T1033
- T1036.010
- T1041
- T1049
- T1053.005
- T1056.001
- T1057
- T1059.001
- T1059.003
- T1069
- T1070.004
- T1074.001
- T1078.002
- T1082
- T1083
- T1087.001
- T1090.002
- T1095
- T1098.007
- T1104
- T1105
- T1110.002
- T1136.001
- T1203
- T1204.001
- T1218.011
- T1543.003
- T1546.008
- T1547.001
- T1552.001
- T1555.003
- T1560.001
- T1564.003
- T1566.002
- T1574.001
Notable Indicators of Compromise (IOCs)
No atomic indicators are listed in this profile. The APTnotes snapshot indexes 4 public reports that may contain IOCs; see Source Attribution for dataset links.
Malware and Tools
- CyberGate
- Cyber Eye RAT
- Shotput:
- Pirpi:
- PlugX/Sogu:
- Kaba:
- Cookie Cutter:
- many 0days: IE:
- Firefox:
- and Flash:
- SportLoader:
- Shadow Brokers exploits:
- DoublePulsar:
- Bemstour:
- Filensfer:
MITRE ATT&CK Software
- OSInfo (S0165) β malware
- schtasks (S0111) β tool
- PlugX (S0013) β malware
- LaZagne (S0349) β tool
- SHOTPUT (S0063) β malware
- RemoteCMD (S0166) β malware
Attribution and Evidence
Country of Origin: China Additional attribution information pending cataloguing.
References
[1] mitre-attack [9] FireEye Clandestine Wolf Eng, E., Caselden, D.. (2015, June 23). Operation Clandestine Wolf β Adobe Flash Zero-Day in APT3 Phishing Campaign. Retrieved January 14, 2016. [10] Recorded Future APT3 May 2017 Insikt Group (Recorded Future). (2017, May 17). Recorded Future Research Concludes Chinese Ministry of State Security Behind APT3. Retrieved September 16, 2024. [11] PWC Pirpi Scanbox Lancaster, T. (2015, July 25). A tale of Pirpi, Scanbox & CVE-2015-3113. Retrieved March 30, 2016. [12] FireEye Operation Double Tap Moran, N., et al. (2014, November 21). Operation Double Tap. Retrieved January 14, 2016. [13] Symantec Buckeye Symantec Security Response. (2016, September 6). Buckeye cyberespionage group shifts gaze from US to Hong Kong. Retrieved September 26, 2016.
Recent News
Latest articles from security news feeds mentioning this actor.
- Trump administration wants nuclear startups to use plutonium for their reactors TechCrunch - 2026-05-26T