APT
ATLAS
Atlas
Actors
147
Names
471
Sectors
40
Requirements
480
⌘K
▸
sign in
Atlas
Actors
147
Names
471
Sectors
40
Requirements
480
LOADING
APT3 (aka UPS Team, Buckeye) · APT Atlas
Actors
/
Nation-state / APT
/
Asia
APT3
G0022
APT
CN · China
AKA
UPS Team · Buckeye · Group 6 · Boyusec · Pirpi
CrowdStrike
:
GOTHIC PANDA
MITRE
:
G0022
Secureworks
:
TG-0110
Targets
9
Sectors
11
Threat types
1
GIRs covered
0/480
Active since
2010
Pin to atlas
Watch
Share
Export
Also tracked as
4 vendor names · 5 other aliases
Open Rosetta Stone
CrowdStrike
GOTHIC PANDA
Mandiant
APT3
MITRE
G0022
Secureworks
TG-0110
UNATTRIBUTED ALIASES
UPS Team
Buckeye
Group 6
Boyusec
Pirpi
Victimology
Geographic footprint · 9 countries
Region filter
Export
origin · China
targeted countries · 9
EUROPE ·
6
Switzerland
·
Germany
·
France
·
United Kingdom
·
Italy
·
Netherlands
ASIA ·
2
Hong Kong
·
India
AMERICAS ·
1
United States
Sectors targeted
11 of 40
Aerospace
59 actors
Financial Services
74 actors
Healthcare
47 actors
Technology
60 actors
NGOs & Dissidents
56 actors
Energy / Utilities
59 actors
Oil and Gas
21 actors
Transportation
31 actors
Industrials / Engineering
29 actors
Chemicals
20 actors
Private Sector (generic)
29 actors
Tactics, techniques, procedures
Threat types + MITRE ATT&CK mapping
THREAT TYPES
ESP · Espionage
MITRE ATT&CK · 32 techniques
Initial Access
· 1
T1566.002
Spearphishing Link
Execution
· 5
T1053.005
Scheduled Task
Persistence
· 2
T1543.003
Windows Service
Credential Access
· 3
T1003.001
LSASS Memory
Discovery
· 6
T1016
System Network Configuration Discovery
Lateral Movement
· 2
T1021.001
Remote Desktop Protocol
T1021.002
Collection
· 2
T1005
Data from Local System
T1560.001
Archive via Utility
Exfiltration
· 1
T1041
Exfiltration Over C2 Channel
Command And Control
· 3
T1095
Non-Application Layer Protocol
Stealth
· 7
T1027
Obfuscated Files or Information
GIR coverage
0 / 480 requirements satisfied
Open matrix
No GIRs mapped yet for this actor.
Open data
Machine-readable exports of this profile
JSON · REST
Actor record
Full profile via the public v1 API
STIX 2.1
Intrusion-set bundle
Deterministic ids · techniques + targeted countries
ATT&CK NAVIGATOR
Technique layer
32 techniques · layer format 4.5
Related actors
By origin and actor type
APT31
nation-state
China · 6 targets · since 2013
APT8
nation-state
China · 5 targets · since —
APT24
nation-state
China · 3 targets · since 2008
APT27
nation-state
China · 23 targets · since 2010
APT44
nation-state
Russia · 25 targets · since 2009
APT21
nation-state
China · 5 targets · since 2010
T1059.001
PowerShell
T1059.003
Windows Command Shell
T1203
Exploitation for Client Execution
T1204.001
Malicious Link
T1547.001
Registry Run Keys / Startup Folder
T1552.001
Credentials In Files
T1555.003
Credentials from Web Browsers
T1018
Remote System Discovery
T1033
System Owner/User Discovery
T1049
System Network Connections Discovery
T1057
Process Discovery
T1083
File and Directory Discovery
SMB/Windows Admin Shares
T1104
Multi-Stage Channels
T1105
Ingress Tool Transfer
T1027.002
Software Packing
T1036.010
Masquerade Account Name
T1070.004
File Deletion
T1078.002
Domain Accounts
T1218.011
Rundll32
T1564.003
Hidden Window