Menu
Browse

Cyber Threat Actor: APT 3

Aliases: 4 aliases
Actor Type Location Known Incidents
 Icon
Nation State
China
1 incident
Profile

APT 3 is a cyber espionage group also known as Gothic Panda, Buckeye and the UPS Team. The group is believed to operate from China and has been linked to state‑sponsored activities by multiple security researchers. Its aliases appear in threat intelligence reports that associate the activity with Chinese governmental interests. Public attribution notes that the group’s actions are consistent with the objectives of a nation‑state sponsor. This background establishes APT 3 as a China‑based actor engaged in espionage‑focused operations.

The group’s known activity includes spear‑phishing campaigns that deliver malicious links and attachments to compromise target networks. In the September 2016 incident against Hong Kong government agencies, APT 3 used emails containing both URLs and malware‑laden files to gain initial access. This approach reflects a reliance on social engineering as a primary initial access vector. The malware used in the attachments was not publicly named in the reporting, but the delivery method aligns with typical espionage tooling. The strategic goal observed in that operation was to gather political intelligence ahead of legislative elections.

The Hong Kong government intrusion is frequently cited as a representative example of APT 3’s operational pattern. It demonstrates the group’s focus on governmental targets in regions of political significance to China. The operation was timed to precede a major electoral event, indicating an intent to influence or monitor the political process. No public reports attribute financial motives or disruptive aims to this activity. Consequently, the available evidence characterizes APT 3 as a state‑linked espionage actor that relies on spear‑phishing to achieve its objectives.

Incidents
Attributed incidents available to members
1 incident
Sources
Sources available to members
0 sources