logo

APT3 (BORON): A Pioneering China-Aligned Cyber Espionage Group

ID: 7da6a9b5-f0a2-5f2e-9eba-3a57ea76b0ec

STIX ID: report--7da6a9b5-f0a2-5f2e-9eba-3a57ea76b0ec

Feed Name: Brandefense Blog

Threat Score
72/100

Date Published: 2026-01-30

Date Updated: 2026-04-27

Author: BRANDEFENSE

...
...

This profile describes APT3 (BORON) as a China-aligned advanced persistent threat focused on cyber espionage against defense contractors, advanced manufacturing, telecoms and government/policy entities; it covers attribution, strategic goals, detailed TTPs (social engineering, watering-hole attacks, rapid exploitation of disclosed vulnerabilities, custom exploit frameworks, modular loaders, credential theft and robust C2), a historical timeline with peak activity from 2012–2016 and reduced visibility after 2017, and defensive takeaways emphasizing patching and detection of legitimate-process abuse.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.