Gold Open Source
ExplorePackagesVulnerabilitiesCWEsMCP ServersScan
Login
Gold Open Source

The authoritative source for production-ready open-source components. Every package, container image, AI model, and MCP server undergoes rigorous verification for security, malware, and license compliance.

Explore Gold

  • Explore Everything
  • Packages
  • Gold Certified Packages
  • Container Images
  • AI Models
  • MCP Servers
  • Agent Skills
  • Chip Manufacturers

Security Data & Tools

  • Scan Your Dependencies
  • Trending Threats
  • Threat RSS Feeds
  • CVE Database
  • Actively Exploited (KEV)
  • SGZ Zero-Days
  • CWE Index
  • MITRE ATT&CK
  • Malicious Packages
  • Security Glossary
  • Supply-Chain Report
  • Developers (API & Badge)
  • Chrome Extension
  • Credits & Data Sources

Products

  • The Platform
  • ESSCM
  • Portal
  • TPRM
  • OSM
  • Cowork
  • Code / Runner
  • Guard

Use Cases

  • Know Your Software
  • Auto-Fix Vulnerabilities
  • Asset Discovery
  • AI Governance
  • MCP Server Security
  • Supply Chain Compliance
  • Zero-Day Discovery
  • All Use Cases

Company

  • About
  • Pricing
  • Blog
  • Documentation
  • Safeguard Academy
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 Gold Open Source. All rights reserved.

Built with care bySafeguard
Home/ATT&CK/Groups/G0022
MITRE ATT&CK Group

APT3 (G0022)

Gothic PandaPirpiUPS TeamBuckeyeThreat Group-0110TG-0110
ShareXLinkedInRedditHN

[APT3](https://attack.mitre.org/groups/G0022) is a China-based threat group that researchers have attributed to China's Ministry of State Security.(Citation: FireEye Clandestine Wolf)(Citation: Recorded Future APT3 May 2017) This group is responsible for the campaigns known as Operation Clandestine Fox, Operation Clandestine Wolf, and Operation Double Tap.(Citation: FireEye Clandestine Wolf)(Citation: FireEye Operation Double Tap) As of June 2015, the group appears to have shifted from targeting primarily US victims to primarily political organizations in Hong Kong.(Citation: Symantec Buckeye)

▪Techniques used (44)

T1053.005Scheduled TaskT1104Multi-Stage ChannelsT1110.002Password CrackingT1564.003Hidden WindowT1555.003Credentials from Web BrowsersT1059.003Windows Command ShellT1016System Network Configuration DiscoveryT1049System Network Connections DiscoveryT1090.002External ProxyT1218.011Rundll32T1027Obfuscated Files or InformationT1566.002Spearphishing LinkT1098.007Additional Local or Domain GroupsT1204.001Malicious LinkT1041Exfiltration Over C2 ChannelT1552.001Credentials In FilesT1074.001Local Data StagingT1078.002Domain AccountsT1005Data from Local SystemT1203Exploitation for Client ExecutionT1021.002SMB/Windows Admin SharesT1574.001DLLT1087.001Local AccountT1070.004File DeletionT1083File and Directory DiscoveryT1546.008Accessibility FeaturesT1560.001Archive via UtilityT1082System Information DiscoveryT1059.001PowerShellT1543.003Windows ServiceT1003.001LSASS MemoryT1547.001Registry Run Keys / Startup FolderT1021.001Remote Desktop ProtocolT1057Process DiscoveryT1095Non-Application Layer ProtocolT1069Permission Groups DiscoveryT1018Remote System DiscoveryT1056.001KeyloggingT1036.010Masquerade Account NameT1027.002Software PackingT1136.001Local AccountT1105Ingress Tool TransferT1033System Owner/User DiscoveryT1027.005Indicator Removal from Tools

▪Software used (6)

S0165OSInfomalwareS0111schtaskstoolS0013PlugXmalwareS0349LaZagnetoolS0063SHOTPUTmalwareS0166RemoteCMDmalware
G0022on MITRE ATT&CK →

MITRE ATT&CK® is a registered trademark of The MITRE Corporation. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation.