LiveActive security incident?Get immediate response
MITRE ATT&CK® Group

G0027: Threat Group-3390

Threat Group-3390 is a Chinese threat group that has extensively used strategic Web compromises to target victims.[1] The group has been active since at least 2010 and has targeted organizations in the aerospace, government, defense, technology, energy, manufacturing and gambling/betting sectors.[2][3][4]

EnterpriseG0027GroupObject v3.0Modified
Glexia's Take · Automated analysis

Security context for executives and security teams

Automation confidenceMedium

G0027: Threat Group-3390 describes [Threat Group-3390](https://attack.mitre.org/groups/G0027) is a Chinese threat group that has extensively used strategic Web compromises to target victims.(Citation: Dell TG-3390) The group has been active since at least 2010 and has targeted organizations in the aerospace, government, defense, technology, energy, manufacturing and gambling/betting sectors.(Citation: SecureWorks BRONZE UNION June 2017)(Citation: Securelist LuckyMouse June 2018)(Citation: Trend Micro DRBControl February 2020)

Executive priority

G0027: Threat Group-3390 is an official MITRE ATT&CK group. Glexia treats it as defensive behavior context for prioritizing monitoring, control validation, and response planning without using the object by itself as an attribution claim.

Technical view

Security teams should validate G0027: Threat Group-3390 by reviewing the official ATT&CK relationships, mapped tactics (the mapped ATT&CK tactic context), supported platforms (the platforms named in the official object), and available local telemetry before making detection or mitigation decisions.

Likely telemetry

  • Official ATT&CK relationships and object metadata

Detection direction

  • Validate whether G0027: Threat Group-3390 appears in your detection coverage and tabletop scenarios.
  • Use the object to align executive risk language with SOC, incident response, and detection engineering work.
  • Do not treat ATT&CK relationship context as attribution without corroborating evidence.

Mitigation priorities

  • Map the object to existing controls and identify missing telemetry or response ownership.
  • Prioritize mitigations that reduce exposure on the listed platforms and tactics.
  • Review adjacent ATT&CK relationships before changing policy, detections, or reporting language.
Additional notes and limits

Baseline Glexia take generated from the official MITRE ATT&CK STIX object, source hash, tactics, platforms, and detection fields. It is safe to replace with a richer model-generated take for the same source hash later.

This baseline take is source-grounded and schema-validated, but it does not include environment-specific telemetry, incident evidence, or threat-intelligence corroboration.

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Official MITRE ATT&CK definition

Threat Group-3390

Threat Group-3390 is a Chinese threat group that has extensively used strategic Web compromises to target victims.[1] The group has been active since at least 2010 and has targeted organizations in the aerospace, government, defense, technology, energy, manufacturing and gambling/betting sectors.[2][3][4]

View the same entry on attack.mitre.org (MITRE-hosted reference; in-page links above use the Glexia ATT&CK library.)

Glexia analysis

How security teams should use this page

Treat this object as behavior context, not an attribution claim. Validate the related groups, software, data sources, and mitigations against official ATT&CK relationships and your own telemetry before making control-coverage decisions.

ATT&CK relationship table

Techniques used

This mirrors the MITRE pattern of making group, software, campaign, and technique relationships scannable. Relationship notes come from mirrored ATT&CK relationship text when available.

56 rows
DomainIDNameRelationship / procedure
EnterpriseT1068Exploitation for Privilege Escalation

Threat Group-3390 has used CVE-2014-6324 and CVE-2017-0213 to escalate privileges.[2]CitationProfero APT27 December 2020

EnterpriseT1030Data Transfer Size Limits

Threat Group-3390 actors have split RAR files for exfiltration into parts.[1]

EnterpriseT1190Exploit Public-Facing Application

Threat Group-3390 has exploited the Microsoft SharePoint vulnerability CVE-2019-0604 and CVE-2021-26855, CVE-2021-26857, CVE-2021-26858, and CVE-2021-27065 in Exchange Server.[5]

EnterpriseT1046Network Service Discovery

Threat Group-3390 actors use the Hunter tool to conduct network service discovery for vulnerable systems.[1][6]

EnterpriseT1053.002AtSub-technique

Threat Group-3390 actors use at to schedule tasks to run self-extracting RAR archives, which install HTTPBrowser or PlugX on other victims on a network.[1]

EnterpriseT1055.012Process HollowingSub-technique

A Threat Group-3390 tool can spawn `svchost.exe` and inject the payload into that process.[7][3]

EnterpriseT1074.001Local Data StagingSub-technique

Threat Group-3390 has locally staged encrypted archives for later exfiltration efforts.[2]

EnterpriseT1203Exploitation for Client Execution

Threat Group-3390 has exploited CVE-2018-0798 in Equation Editor.[5]

EnterpriseT1567.002Exfiltration to Cloud StorageSub-technique

Threat Group-3390 has exfiltrated stolen data to Dropbox.[4]

EnterpriseT1003.001LSASS MemorySub-technique

Threat Group-3390 actors have used a modified version of Mimikatz called Wrapikatz to dump credentials. They have also dumped credentials from domain controllers.[1][2]

EnterpriseT1059.003Windows Command ShellSub-technique

Threat Group-3390 has used command-line interfaces for execution.[2][6]

EnterpriseT1555.005Password ManagersSub-technique

Threat Group-3390 obtained a KeePass database from a compromised host.[4]

EnterpriseT1566.001Spearphishing AttachmentSub-technique

Threat Group-3390 has used e-mail to deliver malicious attachments to victims.[4]

EnterpriseT1012Query Registry

A Threat Group-3390 tool can read and decrypt stored Registry values.[7]

EnterpriseT1003.004LSA SecretsSub-technique

Threat Group-3390 actors have used gsecdump to dump credentials. They have also dumped credentials from domain controllers.[1][2]

EnterpriseT1027.015CompressionSub-technique

Threat Group-3390 malware is compressed with LZNT1 compression.[7][3][6]

EnterpriseT1204.002Malicious FileSub-technique

Threat Group-3390 has lured victims into opening malicious files containing malware.[4]

EnterpriseT1033System Owner/User Discovery

Threat Group-3390 has used `whoami` to collect system user information.[4]

EnterpriseT1608.001Upload MalwareSub-technique

Threat Group-3390 has hosted malicious payloads on Dropbox.[4]

EnterpriseT1505.003Web ShellSub-technique

Threat Group-3390 has used a variety of Web shells.[6]

EnterpriseT1547.001Registry Run Keys / Startup FolderSub-technique

Threat Group-3390's malware can add a Registry key to `Software\Microsoft\Windows\CurrentVersion\Run` for persistence.[7]CitationLunghi Iron Tiger Linux

EnterpriseT1027.013Encrypted/Encoded FileSub-technique

A Threat Group-3390 tool can encrypt payloads using XOR. Threat Group-3390 malware is also obfuscated using Metasploit’s shikata_ga_nai encoder.[7][3][6]

EnterpriseT1543.003Windows ServiceSub-technique

Threat Group-3390's malware can create a new service, sometimes naming it after the config information, to gain persistence.[7]CitationLunghi Iron Tiger Linux

EnterpriseT1199Trusted Relationship

Threat Group-3390 has compromised third party service providers to gain access to victim's environments.CitationProfero APT27 December 2020

EnterpriseT1016System Network Configuration Discovery

Threat Group-3390 actors use NBTscan to discover vulnerable systems.[1]

EnterpriseT1105Ingress Tool Transfer

Threat Group-3390 has downloaded additional malware and tools, including through the use of `certutil`, onto a compromised host .[1][4]

EnterpriseT1056.001KeyloggingSub-technique

Threat Group-3390 actors installed a credential logger on Microsoft Exchange servers. Threat Group-3390 also leveraged the reconnaissance framework, ScanBox, to capture keystrokes.[1][8][3]

EnterpriseT1059.001PowerShellSub-technique

Threat Group-3390 has used PowerShell for execution.[2][4]

EnterpriseT1078Valid Accounts

Threat Group-3390 actors obtain legitimate credentials using a variety of methods and use them to further lateral movement on victim networks.[1]

EnterpriseT1608.004Drive-by TargetSub-technique

Threat Group-3390 has embedded malicious code into websites to screen a potential victim's IP address and then exploit their browser if they are of interest.[9]

EnterpriseT1588.002ToolSub-technique
EnterpriseT1018Remote System Discovery

Threat Group-3390 has used the net view command.[7]

EnterpriseT1583.001DomainsSub-technique

Threat Group-3390 has registered domains for C2.CitationLunghi Iron Tiger Linux

EnterpriseT1189Drive-by Compromise

Threat Group-3390 has extensively used strategic web compromises to target victims.[1][3]

EnterpriseT1140Deobfuscate/Decode Files or Information

During execution, Threat Group-3390 malware deobfuscates and decompresses code that was encoded with Metasploit’s shikata_ga_nai encoder as well as compressed with LZNT1 compression.[3]

EnterpriseT1003.002Security Account ManagerSub-technique

Threat Group-3390 actors have used gsecdump to dump credentials. They have also dumped credentials from domain controllers.[1][2]

EnterpriseT1133External Remote Services

Threat Group-3390 actors look for and use VPN profiles during an operation to access the network using external VPN services.[1] Threat Group-3390 has also obtained OWA account credentials during intrusions that it subsequently used to attempt to regain access when evicted from a victim network.[2]

EnterpriseT1005Data from Local System

Threat Group-3390 ran a command to compile an archive of file types of interest from the victim user's directories.[2]

EnterpriseT1087.001Local AccountSub-technique

Threat Group-3390 has used net user to conduct internal discovery of systems.[2]

EnterpriseT1195.002Compromise Software Supply ChainSub-technique

Threat Group-3390 has compromised the Able Desktop installer to gain access to victim's environments.[5]

EnterpriseT1548.002Bypass User Account ControlSub-technique

A Threat Group-3390 tool can use a public UAC bypass method to elevate privileges.[7]

EnterpriseT1119Automated Collection

Threat Group-3390 ran a command to compile an archive of file types of interest from the victim user's directories.[2]

EnterpriseT1560.002Archive via LibrarySub-technique

Threat Group-3390 has used RAR to compress, encrypt, and password-protect files prior to exfiltration.[2]

EnterpriseT1027.002Software PackingSub-technique

Threat Group-3390 has packed malware and tools, including using VMProtect.[4][5]

EnterpriseT1588.003Code Signing CertificatesSub-technique

Threat Group-3390 has obtained stolen valid certificates, including from VMProtect and the Chinese instant messaging application Youdu, for their operations.CitationLunghi Iron Tiger Linux

EnterpriseT1047Windows Management Instrumentation

A Threat Group-3390 tool can use WMI to execute a binary.[7]

EnterpriseT1071.001Web ProtocolsSub-technique

Threat Group-3390 malware has used HTTP for C2.[3]

EnterpriseT1070.005Network Share Connection RemovalSub-technique

Threat Group-3390 has detached network shares after exfiltrating files, likely to evade detection.[2]

EnterpriseT1021.006Windows Remote ManagementSub-technique

Threat Group-3390 has used WinRM to enable remote execution.[2]

EnterpriseT1574.001DLLSub-technique

Threat Group-3390 has performed DLL search order hijacking to execute their payload.[7] Threat Group-3390 has also used DLL side-loading, including by using legitimate Kaspersky antivirus variants as well as `rc.exe`, a legitimate Microsoft Resource Compiler.[1][2][3][6]CitationLunghi Iron Tiger Linux

EnterpriseT1070.004File DeletionSub-technique

Threat Group-3390 has deleted existing logs and exfiltrated file archives from a victim.[2][4]

EnterpriseT1685.001Disable or Modify Windows Event LogSub-technique

Threat Group-3390 has used appcmd.exe to disable logging on a victim server.[2]

EnterpriseT1608.002Upload ToolSub-technique

Threat Group-3390 has staged tools, including gsecdump and WCE, on previously compromised websites.[1]

EnterpriseT1112Modify Registry

A Threat Group-3390 tool has created new Registry keys under `HKEY_CURRENT_USER\Software\Classes\` and `HKLM\SYSTEM\CurrentControlSet\services`.[7][5]

EnterpriseT1074.002Remote Data StagingSub-technique

Threat Group-3390 has moved staged encrypted archives to Internet-facing servers that had previously been compromised with China Chopper prior to exfiltration.[2]

EnterpriseT1049System Network Connections Discovery

Threat Group-3390 has used `net use` and `netstat` to conduct internal discovery of systems. The group has also used `quser.exe` to identify existing RDP sessions on a victim.[2]

Associated objects

Groups, software, and campaigns

ToolEnterprise

S0039: Net

The Net utility is a component of the Windows operating system. It is used in command-line operations for control of users, groups, services, and network connections. [1]

Net has a great deal of functionality, [2] much of which is useful for an adversary, such as gathering system and network information for Discovery, moving laterally through SMB/Windows Admin Shares using net use commands, and interacting with services. The net1.exe utility is executed for certain functionality when net.exe is run and can be used directly in commands such as net1 user.

Windows
ToolEnterprise

S0008: gsecdump

gsecdump is a publicly-available credential dumper used to obtain password hashes and LSA secrets from Windows operating systems. [1]

Windows
MalwareEnterprise

S0154: Cobalt Strike

Cobalt Strike is a commercial, full-featured, remote access tool that bills itself as “adversary simulation software designed to execute targeted attacks and emulate the post-exploitation actions of advanced threat actors”. Cobalt Strike’s interactive post-exploit capabilities cover the full range of ATT&CK tactics, all executed within a single, integrated system.[1]

In addition to its own capabilities, Cobalt Strike leverages the capabilities of other well-known tools such as Metasploit and Mimikatz.[1]

LinuxmacOSWindows
ToolEnterprise

S0002: Mimikatz

Mimikatz is a credential dumper capable of obtaining plaintext Windows account logins and passwords, along with many other features that make it useful for testing the security of networks. [1] [2]

Windows
ToolEnterprise

S0357: Impacket

Impacket is an open source collection of modules written in Python for programmatically constructing and manipulating network protocols. Impacket contains several tools for remote service execution, Kerberos manipulation, Windows credential dumping, packet sniffing, and relay attacks.[1]

LinuxmacOSWindows
ToolEnterprise

S0160: certutil

certutil is a command-line utility that can be used to obtain certificate authority information and configure Certificate Services. [1]

Windows
Relationship explorer

All related ATT&CK context

Change history

Object version and sync metadata

The fields below describe the current mirrored snapshot. When Glexia retains multiple ATT&CK source imports, you can open the table to compare the same object across releases (hashes and MITRE timestamps). For MITRE’s own release notes and roadmap, see ATT&CK resources — Updates.

ATT&CK release
19.2
Object version
3.0
Created
Modified
Raw hash
ab7e2c9305450944...
Imported snapshots across ATT&CK releases(2)
ReleaseBundle importedObject versionModifiedStatusRaw hash
19.23.0Current bundleab7e2c930545…
19.13.0Older bundle1e505909bbd3…
Raw source

Mirrored ATT&CK source object

The raw object is retained through the mirrored ATT&CK source bundle and object hash. The raw endpoint returns the exact object from the mirrored bundle when available.

Source references

External references and citations

MITRE external references are preserved separately from Glexia analysis so citations remain traceable to their original source records.

  1. [1]
    Dell TG-3390

    Dell SecureWorks Counter Threat Unit Threat Intelligence. (2015, August 5). Threat Group-3390 Targets Organizations for Cyberespionage. Retrieved August 18, 2018.

    Open source URL
  2. [2]
    SecureWorks BRONZE UNION June 2017

    Counter Threat Unit Research Team. (2017, June 27). BRONZE UNION Cyberespionage Persists Despite Disclosures. Retrieved July 13, 2017.

    Open source URL
  3. [3]
    Securelist LuckyMouse June 2018

    Legezo, D. (2018, June 13). LuckyMouse hits national data center to organize country-level waterholing campaign. Retrieved August 18, 2018.

    Open source URL
  4. [4]
    Trend Micro DRBControl February 2020

    Lunghi, D. et al. (2020, February). Uncovering DRBControl. Retrieved November 12, 2021.

    Open source URL
  5. [5]
    Trend Micro Iron Tiger April 2021

    Lunghi, D. and Lu, K. (2021, April 9). Iron Tiger APT Updates Toolkit With Evolved SysUpdate Malware. Retrieved November 12, 2021.

    Open source URL
  6. [6]
    Unit42 Emissary Panda May 2019

    Falcone, R. and Lancaster, T. (2019, May 28). Emissary Panda Attacks Middle East Government Sharepoint Servers. Retrieved July 9, 2019.

    Open source URL
  7. [7]
    Nccgroup Emissary Panda May 2018

    Pantazopoulos, N., Henry T. (2018, May 18). Emissary Panda – A potential new malicious tool. Retrieved June 25, 2018.

    Open source URL
  8. [8]
    Hacker News LuckyMouse June 2018

    Khandelwal, S. (2018, June 14). Chinese Hackers Carried Out Country-Level Watering Hole Attack. Retrieved August 18, 2018.

    Open source URL
  9. [9]
    Gallagher 2015

    Gallagher, S.. (2015, August 5). Newly discovered Chinese hacking group hacked 100+ websites to use as “watering holes”. Retrieved January 25, 2016.

  10. [10]
    APT27

    (Citation: Nccgroup Emissary Panda May 2018)(Citation: Securelist LuckyMouse June 2018)(Citation: Hacker News LuckyMouse June 2018)(Citation: Trend Micro Iron Tiger April 2021)

  11. [11]
    BRONZE UNION

    (Citation: SecureWorks BRONZE UNION June 2017)(Citation: Nccgroup Emissary Panda May 2018)

  12. [12]
    Earth Smilodon

    (Citation: Trend Micro Iron Tiger April 2021)

  13. [13]
    Emissary Panda

    (Citation: Gallagher 2015)(Citation: Nccgroup Emissary Panda May 2018)(Citation: Securelist LuckyMouse June 2018)(Citation: Hacker News LuckyMouse June 2018)(Citation: Unit42 Emissary Panda May 2019)(Citation: Trend Micro Iron Tiger April 2021)

  14. [14]
    Iron Tiger

    (Citation: Hacker News LuckyMouse June 2018)(Citation: Trend Micro Iron Tiger April 2021)

  15. [15]
    Linen Typhoon

    (Citation: Microsoft Naming Conventions Frequently Updated)

  16. [16]
    LuckyMouse

    (Citation: Securelist LuckyMouse June 2018)(Citation: Hacker News LuckyMouse June 2018)(Citation: Trend Micro Iron Tiger April 2021)

  17. [17]
    Microsoft Naming Conventions Frequently Updated

    Microsoft. (2025, September 8). How Microsoft names threat actors. Retrieved September 10, 2025.

    Open source URL
  18. [18]
    TG-3390

    (Citation: Dell TG-3390)(Citation: Nccgroup Emissary Panda May 2018)(Citation: Hacker News LuckyMouse June 2018)

  19. [19]
    Threat Group-3390

    (Citation: Dell TG-3390)(Citation: Hacker News LuckyMouse June 2018)

  20. [20]
    mitre-attackG0027
    Open source URL
Source and licensing

Source: MITRE ATT&CK®. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation. Glexia is not affiliated with or endorsed by MITRE.