Overview 10 indicators
APT3 is a China-based threat group that researchers have attributed to China's Ministry of State Security. This group is responsible for the campaigns known as Operation Clandestine Fox, Operation Clandestine Wolf, and Operation Double Tap. As of June 2015, the group appears to have shifted from targeting primarily US victims to primarily political organizations in Hong Kong.
| domain | 10 | G0022-domain.txt |
Techniques 44 ATT&CK
Open in ATT&CK Navigator → or download the layer (44 techniques, layer 4.5)
- T1003.001 LSASS Memory
- T1005 Data from Local System
- T1016 System Network Configuration Discovery
- T1018 Remote System Discovery
- T1021.001 Remote Desktop Protocol
- T1021.002 SMB/Windows Admin Shares
- T1027 Obfuscated Files or Information
- T1027.002 Software Packing
- T1027.005 Indicator Removal from Tools
- T1033 System Owner/User Discovery
- T1036.010 Masquerade Account Name
- T1041 Exfiltration Over C2 Channel
- T1049 System Network Connections Discovery
- T1053.005 Scheduled Task
- T1056.001 Keylogging
- T1057 Process Discovery
- T1059.001 PowerShell
- T1059.003 Windows Command Shell
- T1069 Permission Groups Discovery
- T1070.004 File Deletion
- T1074.001 Local Data Staging
- T1078.002 Domain Accounts
- T1082 System Information Discovery
- T1083 File and Directory Discovery
- T1087.001 Local Account
- T1090.002 External Proxy
- T1095 Non-Application Layer Protocol
- T1098.007 Additional Local or Domain Groups
- T1104 Multi-Stage Channels
- T1105 Ingress Tool Transfer
- T1110.002 Password Cracking
- T1136.001 Local Account
- T1203 Exploitation for Client Execution
- T1204.001 Malicious Link
- T1218.011 Rundll32
- T1543.003 Windows Service
- T1546.008 Accessibility Features
- T1547.001 Registry Run Keys / Startup Folder
- T1552.001 Credentials In Files
- T1555.003 Credentials from Web Browsers
- T1560.001 Archive via Utility
- T1564.003 Hidden Window
- T1566.002 Spearphishing Link
- T1574.001 DLL
Software 6
Principal sources 2 reports
Ranked by how many of this actor's indicators each report brought in.
- 5fireeye.com/blog/threat-research/2015/07/demonstrat…
- 5fireeye.com/blog/threat-research/2014/11/operation_…
Related groups 2
What the sources have in common — not a claim that these are the same actor. See the whole graph.
Timeline 10 indicators
Each entry is a batch of indicators that appeared upstream on one date, under the report it was filed with.
No indicator matches. Only the most recent 300 are on this page — the rest are in the JSON.
-
fireeye.com/blog/threat-research/2015/07/demonstrat…
link.angellroofing.com psa.perrydale.com report.perrydale.com rpt.perrydale.com vic.perrydale.com -
fireeye.com/blog/threat-research/2014/11/operation_…
bedircati.com lamb-site.com playboysplus.com -
fireeye.com/blog/threat-research/2014/11/operation_…
securitywap.com walterclean.com
Further reading 7
- pwc.blogs.com/cyber_security_updates/2015/07/pirpi-sc…
- attack.mitre.org/groups/G0022
- web.archive.org/web/20160910124439/http://www.symantec.…
- fireeye.com/blog/threat-research/2014/11/operation_…
- fireeye.com/blog/threat-research/2015/06/operation-…
- recordedfuture.com/research/chinese-mss-behind-apt3
- fireeye.com/blog/threat-research/2015/07/demonstrat…