logo

APT3__2016__Buckeye.cyberespionage.group.shifts.gaze.from.US.to.Hong.Kong.-.Symantec.pdf

ID: c21dab08-c730-4b42-ae54-f0cc3a5a143c

STIX ID: report--c21dab08-c730-4b42-ae54-f0cc3a5a143c

Threat Score

85/100

Uploaded: 2026-08-14

Published Date: 2016-10-02

Last Modified Date: 2016-10-02

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Symantec reports that the Buckeye (APT3/Gothic Panda) cyberespionage group has shifted focus from the US to Hong Kong political entities since mid-2015, using spear-phishing with malicious .zip/.lnk attachments to deliver Backdoor.Pirpi and a suite of customized and repurposed tools (keylogger, remote command tools, credential dumpers), leveraging zero-day IE/Flash exploits historically; the report includes detailed IoCs (domains, URLs, SHA256 hashes), victim counts and timelines, and vendor detections.