APT 3, Gothic Panda, Buckeye

Description

(Recorded Future) APT3 (also known as UPS, Gothic Panda, and TG-0110) is a sophisticated threat group that has been active since at least 2010. APT3 utilizes a broad range of tools and techniques including spear-phishing attacks, zero-day exploits, and numerous unique and publicly available remote access tools (RAT). Victims of APT3 intrusions include companies in the defense, telecommunications, transportation, and advanced technology sectors — as well as government departments and bureaus in Hong Kong, the U.S., and several other countries.

Names

NameName-Giver
APT 3Mandiant
Gothic PandaCrowdStrike
BuckeyeSymantec
TG-0110SecureWorks
Bronze MayfairSecureWorks
UPS TeamSymantec
Group 6Talos
Red SylvanPWC
Brocade TyphoonMicrosoft

Country

State-sponsored, Ministry of State Security and Internet security firm Guangzhou Bo Yu Information Technology Company Limited (“Boyusec”)

Motivation

  • Information theft and espionage

First Seen

2007

Observed Sectors

Observed Countries

Tools

Operations

Counter Operations

Information

Mitre Attack

Other Information

Uuid

92ced576-2522-4b79-8645-baa5e84ffee3

Last Card Change

2025-06-28