Also known as: Earth Smilodon, TG-3390, Emissary Panda, BRONZE UNION, APT27, Iron Tiger, LuckyMouse, Linen Typhoon, TEMP.Hippo, Group 35, ZipToken, GreedyTaotie, Red Phoenix, Budworm, Lucky Mouse, G0027, Iron Taurus, Circle Typhoon, DEV-0322, SHORE CASTLE
Threat Group-3390 is a Chinese threat group that has extensively used strategic Web compromises to target victims.(Citation: Dell TG-3390) The group has been active since at least 2010 and has targeted organizations in the aerospace, government, defense, technology, energy, manufacturing and gambling/betting sectors.(Citation: SecureWorks BRONZE UNION June 2017)(Citation: Securelist LuckyMouse June 2018)(Citation: Trend Micro DRBControl February 2020)
Iron Tiger; A Tale of Two Targets DLL Side-Loading: thinprobe.exe → thinhostprobedll.dll (Symantec)
Targeted Sectors
Executive Summary
Threat Group-3390, also known as Emissary Panda, BRONZE UNION, and other aliases, is a Chinese-speaking threat group primarily involved in espionage activities. The group has been active since at least 2010 and has targeted sectors including government, aerospace, and technology. Known for using sophisticated tactics such as web compromises, DLL side-loading, and leveraging custom tools like RCSession and PlugX, Threat Group-3390 poses a significant threat to organizations in critical industries.
Goals & Targeting
Threat Group-3390 appears to operate primarily with the goal of conducting espionage activities. Their targeting profile focuses on sectors that hold significant strategic value, including government, defense, aerospace, technology, energy, manufacturing, and gambling/betting industries. While their exact motivations for targeting these sectors remain unclear, it is reasonable to assume they seek sensitive information or intelligence that could benefit Chinese interests. The group's campaigns have been observed across multiple regions and industries, indicating a broad geographic reach.
Enhanced Description
Threat Group-3390 is a Chinese-based advanced persistent threat (APT) group known for its long-standing involvement in espionage campaigns targeting high-value sectors such as government, aerospace, defense, and technology. The group has demonstrated a high level of operational sophistication, employing techniques such as DLL side-loading and malicious web compromise to gain unauthorized access to target systems. They have also been observed using various tools, including RCSession, ASPXSpy, PlugX, and Cobalt Strike, to achieve their objectives. Over the years, Threat Group-3390 has shown a particular focus on data exfiltration, likely for strategic or intelligence-gathering purposes. The group's ability to remain active since at least 2010 underscores its resilience and adaptability in evolving cybersecurity landscapes.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
Threat Group-3390 has been involved in multiple campaigns, including the 'Iron Tiger; A Tale of Two Targets' operation, which highlights their ability to target diverse industries. Their campaigns often involve strategic web compromises and sophisticated techniques such as DLL side-loading. The group's operational tempo appears steady, with continuous activity over the years. Notable operations include targeting government agencies, defense contractors, and technology firms, where they likely seek sensitive data.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
Based on publicly available data, there is high confidence in the characterization of Threat Group-3390 as a Chinese-speaking APT group involved in espionage. However, specific details about their exact origins, exact targeted countries beyond mentioned sectors, and the full extent of their activities remain unclear. Additional intelligence regarding their infrastructure, campaign timelines, and victimology could provide deeper insight.
Iron Tiger
A Tale of Two Targets
No observed data linked yet.
58
Techniques
20
Tools
2
Campaigns
1
IOCs
0
Observed Data
14
Tactics