logo

Recorded Future Research Concludes Chinese Ministry of State Security Behind APT3

ID: 6de777d7-7c64-4c01-8553-476795c4b9d1

STIX ID: report--6de777d7-7c64-4c01-8553-476795c4b9d1

Threat Score

90/100

Uploaded: 2026-08-14

Published Date: 2017-05-17

Last Modified Date: 2017-05-17

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Recorded Future's analysis attributes the APT3 (aka UPS / Gothic Panda / TG-0110) intrusion group to Guangzhou Boyu Information Technology (Boyusec) operating on behalf of China's Ministry of State Security (MSS). The report consolidates domain/WHOIS/IP evidence, Boyusec's partnerships with Guangdong ITSEC and Huawei, job postings, and prior media reporting to link Boyusec to MSS-directed espionage; it describes APT3's TTPs (spearphishing, zero-day exploits, RATs), broad victimology across defense, telecom, and technology sectors, and recommends organizations re-evaluate security controls and prior intrusions for APT3 activity.