APT3

G0022

Threat group.View on attack.mitre.org

About this group

APT3 is a China-based threat group that researchers have attributed to China's Ministry of State Security. This group is responsible for the campaigns known as Operation Clandestine Fox, Operation Clandestine Wolf, and Operation Double Tap. As of June 2015, the group appears to have shifted from targeting primarily US victims to primarily political organizations in Hong Kong.

Techniques used44

Procedure examples44

TechniqueProcedure example
T1003.001
LSASS Memory

APT3 has used a tool to dump credentials by injecting itself into lsass.exe and triggering with the argument "dig."

T1005
Data from Local System

APT3 will identify Microsoft Office documents on the victim's computer.

T1016
System Network Configuration Discovery

A keylogging tool used by APT3 gathers network information from the victim, including the MAC address, IP address, WINS, DHCP server, and gateway.

T1018
Remote System Discovery

APT3 has a tool that can detect the existence of remote systems.

T1021.001
Remote Desktop Protocol

APT3 enables the Remote Desktop Protocol for persistence. APT3 has also interacted with compromised systems to browse and copy files through RDP sessions.

T1021.002
SMB/Windows Admin Shares

APT3 will copy files over to Windows Admin Shares (like ADMIN$) as part of lateral movement.

T1027
Obfuscated Files or Information

APT3 obfuscates files or information to help evade defensive measures.

T1027.002
Software Packing

APT3 has been known to pack their tools.

T1027.005
Indicator Removal from Tools

APT3 has been known to remove indicators of compromise from tools.

T1033
System Owner/User Discovery

An APT3 downloader uses the Windows command "cmd.exe" /C whoami to verify that it is running with the elevated privileges of “System.”

T1036.010
Masquerade Account Name

APT3 has been known to create or enable accounts, such as support_388945a0.

T1041
Exfiltration Over C2 Channel

APT3 has a tool that exfiltrates data over the C2 channel.

T1049
System Network Connections Discovery

APT3 has a tool that can enumerate current network connections.

T1053.005
Scheduled Task

An APT3 downloader creates persistence by creating the following scheduled task: schtasks /create /tn "mysc" /tr C:\Users\Public\test.exe /sc ONLOGON /ru "System".

T1056.001
Keylogging

APT3 has used a keylogging tool that records keystrokes in encrypted files.

View all 44 procedure examples

Software6

Campaigns0

None recorded.

References4

  1. FireEye Clandestine Wolf Open source
    Eng, E., Caselden, D.. (2015, June 23). Operation Clandestine Wolf – Adobe Flash Zero-Day in APT3 Phishing Campaign. Retrieved January 14, 2016.
  2. FireEye Operation Double Tap Open source
    Moran, N., et al. (2014, November 21). Operation Double Tap. Retrieved January 14, 2016.
  3. Recorded Future APT3 May 2017 Open source
    Insikt Group (Recorded Future). (2017, May 17). Recorded Future Research Concludes Chinese Ministry of State Security Behind APT3. Retrieved September 16, 2024.
  4. Symantec Buckeye Open source
    Symantec Security Response. (2016, September 6). Buckeye cyberespionage group shifts gaze from US to Hong Kong. Retrieved September 26, 2016.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.