Researchers and independent investigators tied the Chinese cyber-espionage group APT3—also tracked as Gothic Panda, Buckeye, UPS Team, and TG-0110—to long-running intrusions targeting government, research, technology, aerospace, defense, transport, manufacturing, and telecommunications organizations. Reporting says the group used spear-phishing, browser and Flash zero-day exploits including CVE-2014-1776, CVE-2014-6332, and CVE-2015-3113, then deployed the Pirpi remote access trojan to move laterally, install backdoors, and steal intellectual property and other confidential data, initially focusing on the United States and United Kingdom before expanding activity to Hong Kong.
Technical analysis found APT3 repeatedly reused exploit components, shellcode, steganographic delivery through animated GIFs, and command-and-control patterns across campaigns, with Pirpi variants sharing encrypted HTTP cookie-based communications and similar command loops while newer builds added stronger obfuscation and anti-analysis features. Separate attribution research claimed historic DNS and WHOIS records linked infrastructure such as httb[.]net, vcersoft[.]com, uyre[.]net, inc-work[.]com, microsoft-ie[.]com, unixfocus[.]net, and shuyan[.]com to alleged operators including Wu Yingzhuo and Dong Hao, arguing that shared registration artifacts exposed personnel behind the espionage activity.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
12 events from the most recent confirmed update back to the earliest known activity.
Intrusion Truth published an attribution chain linking Dong Hao to domains and registration artifacts associated with infrastructure previously tied to Wu Yingzhuo. The article concluded Dong Hao was a second alleged APT3 operator involved in registering domain names.
Intrusion Truth published research tracing historic WHOIS, DNS, and alias data from Pirpi-linked domains to an individual it identified as Wu Yingzhuo, alleging he was the 'Mr Wu' behind parts of APT3 infrastructure. The article also linked related domains and IP data to Guangdong, China, as further attribution context.
Intrusion Truth published a profile of APT3 describing its aliases, targeting, malware, and infrastructure tradecraft, and asserting that domain registration metadata could identify people and entities behind the group. The article also referenced a follow-up claim linking APT3 to Boyusec, described as a Chinese intelligence contractor.
Six months after Intrusion Truth's 2017 attribution reporting, U.S. authorities unsealed indictments against Wu Yingzhuo, Dong Hao, and Xia Lei on hacking-related charges. The indictment identified Trimble, Siemens, and Moody's Analytics as U.S. victims.
APT3 infections in Hong Kong increased significantly in March 2016, according to the reporting summarized in the reference. This indicated a notable escalation of the group's activity there.
Unit 42 reported that UPS exploited zero-days exposed in the Hacking Team breach. This connected the group to another set of high-end exploit operations in 2015.
FireEye published a blog post titled "Operation Clandestine Wolf" describing APT3 exploitation of an Adobe Flash zero-day. The reporting publicly documented the group's use of the vulnerability in active espionage operations.
Adobe patched CVE-2015-3113, a Flash zero-day that UPS had exploited in espionage activity. The vulnerability was part of a broader cluster of zero-day campaigns tied to the group.
Symantec reported that APT3 had begun infecting organizations in Hong Kong, marking an expansion beyond its earlier focus on the United States and United Kingdom. This represented a geographic shift in the group's victimology.
UPS exploited CVE-2014-6332 in a later 2014 campaign. FireEye reported the group used VBScript for this exploitation, and Unit 42 noted code and naming overlaps with other UPS zero-day activity.
APT3, tracked by Unit 42 as UPS, exploited CVE-2014-1776 in campaigns that delivered a Pirpi payload. Unit 42 later identified shared exploit and payload components linking this activity to later UPS operations.
FireEye first reported the cyber espionage group later tracked as APT3 in 2010. The group was associated with the Pirpi remote access trojan and targeting in the United States and United Kingdom.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
7 references tracked. Mallory keeps watching after this page renders.
intrusiontruth.wordpress.com
Open sourceintrusiontruth.wordpress.com
Open sourceintrusiontruth.wordpress.com
Open sourceintrusiontruth.wordpress.com
Open sourceresearchcenter.paloaltonetworks.com
Open sourcefireeye.com
Open sourcesymantec.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.