Threat Group-3390

MITRE ATT&CK: G0027 View on attack.mitre.org

Aliases: Earth Smilodon, TG-3390, Emissary Panda, BRONZE UNION, APT27, Iron Tiger, LuckyMouse, Linen Typhoon, GreedyTaotie, EMISSARY PANDA, TEMP.Hippo, Red Phoenix, Budworm, Group 35, ZipToken, Lucky Mouse, Iron Taurus, Circle Typhoon, Threat Group-3390, DEV-0322, APT6, IODINE, Hippo, BOWSER, Wekby2, UNC215

First seen
2010-01-01 00:00:00
Origin
CN
Primary motivation
espionage
Sophistication
advanced
Resource level
government
Actor type
Espionage
Related IoCs
40 (39 malicious)
Last IoC activity
2026-08-27 00:00:27
Profile updated
2026-07-07 12:31:09

Targeted industries: defense-and-aerospace government-and-public-sector technology-and-telecommunications energy-and-utilities manufacturing

Targeted regions: country_code:us country_code:gb country_code:jp country_code:de country_code:in

Context

Threat Group-3390 is a Chinese threat group that has extensively used strategic Web compromises to target victims. The group has been active since at least 2010 and has targeted organizations in the aerospace, government, defense, technology, energy, manufacturing and gambling/betting sectors.

Recent IoC activity

39 malicious indicators in Maltiverse are attributed to Threat Group-3390 (G0027). The 20 most recently updated:

Detection coverage

  • 184 YARA rules
  • 816 Sigma rules

Malware & tools used

  • Exploitation for Privilege Escalation (attack-pattern)
  • Data Transfer Size Limits (attack-pattern)
  • Exploit Public-Facing Application (attack-pattern)
  • Network Service Discovery (attack-pattern)
  • At (attack-pattern)
  • Process Hollowing (attack-pattern)
  • Local Data Staging (attack-pattern)
  • Exploitation for Client Execution (attack-pattern)
  • Exfiltration to Cloud Storage (attack-pattern)
  • LSASS Memory (attack-pattern)
  • Windows Command Shell (attack-pattern)
  • Password Managers (attack-pattern)
  • Spearphishing Attachment (attack-pattern)
  • Query Registry (attack-pattern)
  • LSA Secrets (attack-pattern)
  • Compression (attack-pattern)
  • Malicious File (attack-pattern)
  • System Owner/User Discovery (attack-pattern)
  • Upload Malware (attack-pattern)
  • Web Shell (attack-pattern)
  • Registry Run Keys / Startup Folder (attack-pattern)
  • Encrypted/Encoded File (attack-pattern)
  • Windows Service (attack-pattern)
  • Trusted Relationship (attack-pattern)
  • System Network Configuration Discovery (attack-pattern)

Reports & references

  • Mandiant — Apt Groups (report)
  • cloud.google.com — Updated Cyber Threat Actor Naming System (report)
  • i.blackhat.com — As 22 Li To Loot Or Not To Loot That Is Not A Question (report)
  • web.archive.org — 330401 (report)
  • labs.bitdefender.com — Operation Pzchao A Possible Return Of The Iron Tiger Apt (report)
  • bitdefender.com — Bitdefender Business 2017 Whitepaper Pzchao Crea2452 En En Genericuse (report)
  • cfr.org — Iron Tiger (report)
  • bleepingcomputer.com — Chinese Cyber Espionage Group Hacked Government Data Center (report)
  • secureworks.com — Bronze Union (report)
  • Trend Micro — Operation Iron Tiger Attackers Shift East Asia United States (report)
  • secureworks.com — Threat Group 3390 Targets Organizations For Cyberespionage (report)
  • threatconnect.com — Threatconnect Discovers Chinese Apt Activity In Europe (report)
  • nccgroup.trust — Decoding Network Data From A Gh0St Rat Variant (report)
  • Kaspersky — 87914 (report)
  • paper.seebug.org — Operation%20Iron%20Tiger%20Appendix (report)
  • arstechnica.com — Newly Discovered Chinese Hacking Group Hacked 100 Websites To Use As Watering Holes (report)
  • Kaspersky — 86083 (report)
  • MITRE ATT&CK — G0027 (report)
  • secureworks.com — Bronze Union (report)
  • Palo Alto Unit 42 — Iron Taurus (report)
  • pwc.co.uk — Pwc Cyber Threats 2020 A Year In Retrospect (report)
  • ESET — Exchange Servers Under Siege 10 Apt Groups (report)
  • Trend Micro — Iron Tiger Apt Updates Toolkit With Evolved Sysupdate Malware Va (report)
  • raw.githubusercontent.com — Microsoftmapping (report)
  • Microsoft — Microsoft Threat Actor Naming (report)

External references