APT3__2016__Buckeye.cyberespionage.group.shifts.gaze.from.US.to.Hong.Kong.-.Symantec.pdf
ID: c21dab08-c730-4b42-ae54-f0cc3a5a143c
STIX ID: report--c21dab08-c730-4b42-ae54-f0cc3a5a143c
Threat Score
85/100
Uploaded: 2026-08-14
Published Date: 2016-10-02
Last Modified Date: 2016-10-02
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Symantec reports that the Buckeye (APT3/Gothic Panda) cyberespionage group has shifted focus from the US to Hong Kong political entities since mid-2015, using spear-phishing with malicious .zip/.lnk attachments to deliver Backdoor.Pirpi and a suite of customized and repurposed tools (keylogger, remote command tools, credential dumpers), leveraging zero-day IE/Flash exploits historically; the report includes detailed IoCs (domains, URLs, SHA256 hashes), victim counts and timelines, and vendor detections.
