G0027 · 57 ATT&CK techniques · 0 correlated reports

Threat Group-3390

Aliases: Earth Smilodon, TG-3390, Emissary Panda, BRONZE UNION, APT27, Iron Tiger, LuckyMouse

Threat Group-3390 is a Chinese threat group that has extensively used strategic Web compromises to target victims. The group has been active since at least 2010 and has targeted organizations in the aerospace, government, defense, technology, energy, manufacturing and gambling/betting sectors.

Open interactive actor investigation

ATT&CK techniques

T1068
Exploitation for Privilege Escalation
T1030
Data Transfer Size Limits
T1190
Exploit Public-Facing Application
T1046
Network Service Discovery
T1053.002
At
T1055.012
Process Hollowing
T1074.001
Local Data Staging
T1203
Exploitation for Client Execution
T1567.002
Exfiltration to Cloud Storage
T1003.001
LSASS Memory
T1059.003
Windows Command Shell
T1574.002
DLL Side-Loading
T1555.005
Password Managers
T1566.001
Spearphishing Attachment
T1012
Query Registry
T1003.004
LSA Secrets
T1204.002
Malicious File
T1033
System Owner/User Discovery
T1608.001
Upload Malware
T1505.003
Web Shell
T1547.001
Registry Run Keys / Startup Folder
T1027.013
Encrypted/Encoded File
T1543.003
Windows Service
T1199
Trusted Relationship
T1016
System Network Configuration Discovery
T1105
Ingress Tool Transfer
T1056.001
Keylogging
T1059.001
PowerShell
T1562.002
Disable Windows Event Logging
T1078
Valid Accounts
T1608.004
Drive-by Target
T1588.002
Tool
T1018
Remote System Discovery
T1583.001
Domains
T1189
Drive-by Compromise
T1140
Deobfuscate/Decode Files or Information
T1003.002
Security Account Manager
T1133
External Remote Services
T1005
Data from Local System
T1087.001
Local Account
T1195.002
Compromise Software Supply Chain
T1548.002
Bypass User Account Control
T1119
Automated Collection
T1560.002
Archive via Library
T1027.002
Software Packing
T1588.003
Code Signing Certificates
T1047
Windows Management Instrumentation
T1071.001
Web Protocols
T1070.005
Network Share Connection Removal
T1021.006
Windows Remote Management
T1574.001
DLL Search Order Hijacking
T1070.004
File Deletion
T1608.002
Upload Tool
T1112
Modify Registry
T1210
Exploitation of Remote Services
T1074.002
Remote Data Staging
T1049
System Network Connections Discovery

Correlated CTI and IR reports

Continue the investigation