Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors Threat Group-3390

Also known as: Earth Smilodon, TG-3390, Emissary Panda, BRONZE UNION, APT27, Iron Tiger, LuckyMouse, Linen Typhoon, TEMP.Hippo, Group 35, ZipToken, GreedyTaotie, Red Phoenix, Budworm, Lucky Mouse, G0027, Iron Taurus, Circle Typhoon, DEV-0322, SHORE CASTLE

Description

Threat Group-3390 is a Chinese threat group that has extensively used strategic Web compromises to target victims.(Citation: Dell TG-3390) The group has been active since at least 2010 and has targeted organizations in the aerospace, government, defense, technology, energy, manufacturing and gambling/betting sectors.(Citation: SecureWorks BRONZE UNION June 2017)(Citation: Securelist LuckyMouse June 2018)(Citation: Trend Micro DRBControl February 2020)

TTP Summary

Iron Tiger; A Tale of Two Targets DLL Side-Loading: thinprobe.exe → thinhostprobedll.dll (Symantec)

Goals & Targeting

Targeted Sectors

Think tank
Government

AI Analysis

· 1 week ago

Executive Summary

Threat Group-3390, also known as Emissary Panda, BRONZE UNION, and other aliases, is a Chinese-speaking threat group primarily involved in espionage activities. The group has been active since at least 2010 and has targeted sectors including government, aerospace, and technology. Known for using sophisticated tactics such as web compromises, DLL side-loading, and leveraging custom tools like RCSession and PlugX, Threat Group-3390 poses a significant threat to organizations in critical industries.

Goals & Targeting

Threat Group-3390 appears to operate primarily with the goal of conducting espionage activities. Their targeting profile focuses on sectors that hold significant strategic value, including government, defense, aerospace, technology, energy, manufacturing, and gambling/betting industries. While their exact motivations for targeting these sectors remain unclear, it is reasonable to assume they seek sensitive information or intelligence that could benefit Chinese interests. The group's campaigns have been observed across multiple regions and industries, indicating a broad geographic reach.

Enhanced Description

Threat Group-3390 is a Chinese-based advanced persistent threat (APT) group known for its long-standing involvement in espionage campaigns targeting high-value sectors such as government, aerospace, defense, and technology. The group has demonstrated a high level of operational sophistication, employing techniques such as DLL side-loading and malicious web compromise to gain unauthorized access to target systems. They have also been observed using various tools, including RCSession, ASPXSpy, PlugX, and Cobalt Strike, to achieve their objectives. Over the years, Threat Group-3390 has shown a particular focus on data exfiltration, likely for strategic or intelligence-gathering purposes. The group's ability to remain active since at least 2010 underscores its resilience and adaptability in evolving cybersecurity landscapes.

Key Capabilities

  • DLL side-loading
  • Web compromises
  • Custom malware development
  • Leverage legitimate frameworks like Cobalt Strike
  • Sophisticated persistence techniques
  • Exploitation of remote services

MITRE ATT&CK Tactics

Initial Access
Persistence
Credential Access
Discovery
Collection
Exfiltration
Impact

ATT&CK Techniques

T1056.001: Keylogging
T1027.015: Compression
T1133: External Remote Services
T1074.001: Local Data Staging
T1685.001: Disable or Modify Windows Event Log
T1003.002: Security Account Manager
T1003.004: LSA Secrets
T1204.002: Malicious File
T1574.001: DLL
T1119: Automated Collection
T1555.005: Password Managers
T1074.002: Remote Data Staging
T1005: Data from Local System
T1190: Exploit Public-Facing Application

Software / Tooling

RCSession
ASPxSpy
China Chopper
HyperBro
PlugX
Clambling
gh0st RAT
Pandora
Cobalt Strike
SysUpdate
ZxShell
HTTPBrowser

Campaigns & Victims

Threat Group-3390 has been involved in multiple campaigns, including the 'Iron Tiger; A Tale of Two Targets' operation, which highlights their ability to target diverse industries. Their campaigns often involve strategic web compromises and sophisticated techniques such as DLL side-loading. The group's operational tempo appears steady, with continuous activity over the years. Notable operations include targeting government agencies, defense contractors, and technology firms, where they likely seek sensitive data.

IOC Patterns

  • Spear-phishing with malicious links or attachments
  • DLL files related to known tools like RCSession and PlugX
  • Network traffic indicative of remote exploitation attempts
  • Presence of custom-malware signatures in endpoint logs
  • Anomalies in Windows Event Logs indicating tampering

Recommended Actions

  • Implement multi-factor authentication (MFA) for critical systems.
  • Monitor for异常网络流量和DLL加载行为.
  • Conduct regular checks on remote access protocols and services.
  • Deploy endpoint detection and response (EDR) solutions to detect advanced threats.
  • Educate employees about phishing tactics and suspicious emails.
  • Regularly update software and patch known vulnerabilities.

Suggested Tags

APT
espionage
government
defense
technology

Confidence Assessment

Based on publicly available data, there is high confidence in the characterization of Threat Group-3390 as a Chinese-speaking APT group involved in espionage. However, specific details about their exact origins, exact targeted countries beyond mentioned sectors, and the full extent of their activities remain unclear. Additional intelligence regarding their infrastructure, campaign timelines, and victimology could provide deeper insight.

ATT&CK Techniques

Collection
6 techniques
Credential Access
4 techniques
Discovery
7 techniques
Execution
6 techniques
Initial Access
5 techniques
Persistence
4 techniques
Resource Development
6 techniques
Stealth
9 techniques

Software / Tooling

Observed Data

No observed data linked yet.

Indicators of Compromise

IPv4 Address 1

References

  1. SecureWorks BRONZE UNION June 2017 — Counter Threat Unit Research Team. (2017, June 27). BRONZE UNION Cyberespionage Persists Despite Disclosures. Retrieved July 13, 2017.
  2. Dell TG-3390 — Dell SecureWorks Counter Threat Unit Threat Intelligence. (2015, August 5). Threat Group-3390 Targets Organizations for Cyberespionage. Retrieved August 18, 2018.
  3. Unit42 Emissary Panda May 2019 — Falcone, R. and Lancaster, T. (2019, May 28). Emissary Panda Attacks Middle East Government Sharepoint Servers. Retrieved July 9, 2019.
  4. Gallagher 2015 — Gallagher, S.. (2015, August 5). Newly discovered Chinese hacking group hacked 100+ websites to use as “watering holes”. Retrieved January 25, 2016.
  5. Hacker News LuckyMouse June 2018 — Khandelwal, S. (2018, June 14). Chinese Hackers Carried Out Country-Level Watering Hole Attack. Retrieved August 18, 2018.
  6. Securelist LuckyMouse June 2018 — Legezo, D. (2018, June 13). LuckyMouse hits national data center to organize country-level waterholing campaign. Retrieved August 18, 2018.
  7. Trend Micro Iron Tiger April 2021 — Lunghi, D. and Lu, K. (2021, April 9). Iron Tiger APT Updates Toolkit With Evolved SysUpdate Malware. Retrieved November 12, 2021.
  8. Trend Micro DRBControl February 2020 — Lunghi, D. et al. (2020, February). Uncovering DRBControl. Retrieved November 12, 2021.
  9. Microsoft Naming Conventions Frequently Updated — Microsoft. (2025, September 8). How Microsoft names threat actors. Retrieved September 10, 2025.
  10. Nccgroup Emissary Panda May 2018 — Pantazopoulos, N., Henry T. (2018, May 18). Emissary Panda – A potential new malicious tool. Retrieved June 25, 2018.

Intel Summary

58

Techniques

20

Tools

2

Campaigns

1

IOCs

0

Observed Data

14

Tactics

Tags

APT
Government Targeting
espionage
government
defense
technology

Details

MITRE ID
G0027
Type
Unknown
Resource Level
Government
Primary Motivation
Espionage
Country of Origin
China (CN)
Confidence
90%
Added
May 2, 2026
STIX ID
intrusion-set--fb366179-766c-4a4a-afa1-52bff1fd601c
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.