APT3 is a threat actor also referred to in the provided content as Pirpi, Boron, Brocade Typhoon, Buckeye, Cybron, Gothic Panda, OldCarp, Red Sylvan, TG-0110, Threat Group-0110, UPS, and UPS Team. The content describes APT3 activity across multiple ATT&CK behaviors including PowerShell execution, privilege escalation, Windows service persistence, local data collection, file and directory discovery, system information discovery, network configuration discovery, user discovery, credential access, and artifact deletion. Observed behaviors in the provided content include placing scripts in the Startup folder for persistence; creating a new service for persistence; using PowerShell with -WindowStyle Hidden to conceal execution; using cmd.exe /C whoami to verify SYSTEM-level privileges; establishing SOCKS5 connections for initial command and control; identifying Microsoft Office documents on victim systems; listing running processes; searching for files and directories on the local file system; staging files for exfiltration in a single location; deleting files; obtaining local system information; gathering network information including MAC address, IP address, WINS, DHCP server, and gateway; dumping passwords from browsers; locating credentials in files on disk including Firefox and Chrome-related files; and using a tool that dumped credentials by injecting into lsass.exe. The content directly associates APT3 with ATT&CK techniques including T1059.001 PowerShell, T1068 Exploitation for Privilege Escalation, T1543.003 Windows Service, T1005 Data from Local System, and T1190 Exploit Public-Facing Application.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
52 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
10 malware families attributed to this actor across reporting.
5 additional families tracked in Mallory.
3 CVEs this actor has used in observed campaigns. 3 of them exploited in the wild.
APT3 has exploited... Internet Explorer vulnerability CVE-2014-1776.
APT3 has exploited the Adobe Flash Player vulnerability CVE-2015-3113...
This detection identifies instances where Windows Explorer.exe spawns PowerShell or cmd.exe processes, particularly focusing on executions initiated by LNK files. This behavior is associated with the ZDI-CAN-25373 Windows shortcut zero-day vulnerability, where specially crafted LNK files are used to trigger malicious code execution through cmd.exe or powershell.exe. This technique has been actively exploited by multiple APT groups in targeted attacks through both HTTP and SMB delivery methods.
41 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Listed as an associated threat actor in the detection annotation for exploitation of the public-facing PTC Windchill vulnerability CVE-2026-4681.
Uses credential dumping by injecting tooling into LSASS to extract credentials.
Listed as an associated threat actor for exploitation activity related to abuse of the Windows Cloud Files API / cldapi.dll detection.
Listed as a threat actor associated with PowerShell execution behavior relevant to this detection.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.