Large portions of APT3’s remote code-execution package were likely reverse-engineered from prior attack artifacts.
Source: Threadpost