← Back to all threat actors

APT3

Also known as Gothic Panda, Pirpi, UPS Team, Buckeye, Threat Group-0110, TG-0110
Tracked as G0022

APT3 is a China-based threat group that researchers have attributed to China's Ministry of State Security. This group is responsible for the campaigns known as Operation Clandestine Fox, Operation Clandestine Wolf, and Operation Double Tap. As of June 2015, the group appears to have shifted from targeting primarily US victims to primarily political organizations in Hong Kong.

How we source and review actor profiles
Motivation
nation-state
Sectors
defense, technology, government
Status
Active

Activity timeline

A dated ledger of actor-claimed victims, campaigns, indicators, identity mappings, relationships, and CVE links. Each date states what it measures. For extensive leak-site histories, victim entries are limited to the 100 most recent distinct listings.

Cataloged
IdentityAlias: Gothic Panda

Reviewed identity mapping approved on this date.

Cataloged
IdentityAlias: Pirpi

Reviewed identity mapping approved on this date.

Cataloged
IdentityAlias: UPS Team

Reviewed identity mapping approved on this date.

Cataloged
IdentityAlias: Buckeye

Reviewed identity mapping approved on this date.

Cataloged
IdentityAlias: Threat Group-0110

Reviewed identity mapping approved on this date.

Cataloged
IdentityAlias: TG-0110

Reviewed identity mapping approved on this date.

Cataloged
IdentityTracking identifier: G0022

Reviewed identity mapping approved on this date.

Identity and attribution

Exact names and tracking identifiers resolve to this canonical profile. Rebrands, affiliations, and overlapping clusters remain separate confidence-rated relationships.

Name map

APT3Canonical Name
BuckeyeAlias
Gothic PandaAlias
PirpiAlias
TG-0110Alias
Threat Group-0110Alias
UPS TeamAlias
G0022Tracking Id

Loading CVEs, techniques, indicators, malware, victims, and activity...