Recorded Future Research Concludes Chinese Ministry of State Security Behind APT3
ID: 6de777d7-7c64-4c01-8553-476795c4b9d1
STIX ID: report--6de777d7-7c64-4c01-8553-476795c4b9d1
Threat Score
90/100
Uploaded: 2026-08-14
Published Date: 2017-05-17
Last Modified Date: 2017-05-17
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Recorded Future's analysis attributes the APT3 (aka UPS / Gothic Panda / TG-0110) intrusion group to Guangzhou Boyu Information Technology (Boyusec) operating on behalf of China's Ministry of State Security (MSS). The report consolidates domain/WHOIS/IP evidence, Boyusec's partnerships with Guangdong ITSEC and Huawei, job postings, and prior media reporting to link Boyusec to MSS-directed espionage; it describes APT3's TTPs (spearphishing, zero-day exploits, RATs), broad victimology across defense, telecom, and technology sectors, and recommends organizations re-evaluate security controls and prior intrusions for APT3 activity.
