Threat group.View on attack.mitre.org
APT3 is a China-based threat group that researchers have attributed to China's Ministry of State Security. This group is responsible for the campaigns known as Operation Clandestine Fox, Operation Clandestine Wolf, and Operation Double Tap. As of June 2015, the group appears to have shifted from targeting primarily US victims to primarily political organizations in Hong Kong.
| Technique | Procedure example |
|---|---|
| T1003.001 LSASS Memory |
APT3 has used a tool to dump credentials by injecting itself into lsass.exe and triggering with the argument "dig." |
| T1005 Data from Local System |
APT3 will identify Microsoft Office documents on the victim's computer. |
| T1016 System Network Configuration Discovery |
A keylogging tool used by APT3 gathers network information from the victim, including the MAC address, IP address, WINS, DHCP server, and gateway. |
| T1018 Remote System Discovery |
APT3 has a tool that can detect the existence of remote systems. |
| T1021.001 Remote Desktop Protocol |
APT3 enables the Remote Desktop Protocol for persistence. APT3 has also interacted with compromised systems to browse and copy files through RDP sessions. |
| T1021.002 SMB/Windows Admin Shares |
APT3 will copy files over to Windows Admin Shares (like ADMIN$) as part of lateral movement. |
| T1027 Obfuscated Files or Information |
APT3 obfuscates files or information to help evade defensive measures. |
| T1027.002 Software Packing |
APT3 has been known to pack their tools. |
| T1027.005 Indicator Removal from Tools |
APT3 has been known to remove indicators of compromise from tools. |
| T1033 System Owner/User Discovery |
An APT3 downloader uses the Windows command |
| T1036.010 Masquerade Account Name |
APT3 has been known to create or enable accounts, such as |
| T1041 Exfiltration Over C2 Channel |
APT3 has a tool that exfiltrates data over the C2 channel. |
| T1049 System Network Connections Discovery |
APT3 has a tool that can enumerate current network connections. |
| T1053.005 Scheduled Task |
An APT3 downloader creates persistence by creating the following scheduled task: |
| T1056.001 Keylogging |
APT3 has used a keylogging tool that records keystrokes in encrypted files. |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.