APT3
Attribution profile
- Type
- Nation State
- Location
- China
- Known incidents
- 2 incidents
- Sources
- 2 sources
- First seen
- 2015-01-07
- Last seen
- 2015-12-04
- Updated
- 2026-08-07 00:59
- Aliases
- 3 aliases
STIX characteristics
Threat actor characteristics are available to members.
Profile narrative
APT3, also tracked as Gothic Panda and Buckeye, is a threat actor linked to China, with its operators identified as Chinese nationals residing in China and associated with the China‑based internet security firm Guangzhou Bo Yu Information Technology Company Limited (Boyusec). Public reporting describes the group as Chinese cyberspies, indicating a connection to state‑aligned espionage activities. The actor’s aliases appear across multiple investigations, reflecting a consistent set of operations attributed to the same underlying entity.
The actor’s targeting has been observed in the financial, engineering and technology sectors, where it sought to steal trade secrets and obtain commercial advantage, as detailed in the indictment of three individuals who hacked corporate victims between 2011 and May 2017. In addition, APT3 has directed spear‑phishing campaigns against government entities, notably Hong Kong agencies in the lead‑up to legislative elections, with the motivation characterized as politically driven based on the selected targets. The group’s typical initial access vector involves spear‑phishing emails containing malicious links or attachments designed to deliver malware and establish unauthorized persistence within victim networks.
Notable operations attributed to APT3 include the prolonged intrusion into three corporations across the financial, engineering and technology industries for the purpose of exfiltrating sensitive internal documents and communications. A separate campaign involved multiple spear‑phishing attempts against Hong Kong government organizations in early August 2016, leveraging malware‑laden emails to compromise networks. Earlier, in January 2015, a breach of a prominent Washington, D.C. think tank’s tax‑filing systems exposed extensive nonprofit account data, an incident that aligns with the actor’s pattern of targeting policy organizations for intelligence gathering, although public attribution for that specific event remains unspecified. These examples illustrate the actor’s focus on both commercial theft and politically motivated espionage through recurring use of spear‑phishing and sustained network access.
Incidents
Attributed incidents are available to members.
2 incidentsSources
Sources available to members: 2 sources.