← All actors Recent activity

APT3 G0022

GOTHICPANDA · apt-c-3 · apt3 · ups

Indicators
10
Source reports
2
Activity span
not dated
Newest indicator
unknown
Upstream change
2026-01-02
20182019

Overview 10 indicators

APT3 is a China-based threat group that researchers have attributed to China's Ministry of State Security. This group is responsible for the campaigns known as Operation Clandestine Fox, Operation Clandestine Wolf, and Operation Double Tap. As of June 2015, the group appears to have shifted from targeting primarily US victims to primarily political organizations in Hong Kong.

domain10G0022-domain.txt

Techniques 44 ATT&CK

Open in ATT&CK Navigator → or download the layer (44 techniques, layer 4.5)

Software 6

Principal sources 2 reports

Ranked by how many of this actor's indicators each report brought in.

What the sources have in common — not a claim that these are the same actor. See the whole graph.

Timeline 10 indicators

Each entry is a batch of indicators that appeared upstream on one date, under the report it was filed with.

  1. 5 domain7 yrs ago

    fireeye.com/blog/threat-research/2015/07/demonstrat…

    link.angellroofing.com
    psa.perrydale.com
    report.perrydale.com
    rpt.perrydale.com
    vic.perrydale.com

  2. 3 domain7 yrs ago

    fireeye.com/blog/threat-research/2014/11/operation_…

    bedircati.com
    lamb-site.com
    playboysplus.com

  3. 2 domain8 yrs ago

    fireeye.com/blog/threat-research/2014/11/operation_…

    securitywap.com
    walterclean.com

Further reading 7