Threat Group-3390
MITRE ATT&CK: G0027 View on attack.mitre.org
Aliases: Earth Smilodon, TG-3390, Emissary Panda, BRONZE UNION, APT27, Iron Tiger, LuckyMouse, Linen Typhoon, GreedyTaotie, EMISSARY PANDA, TEMP.Hippo, Red Phoenix, Budworm, Group 35, ZipToken, Lucky Mouse, Iron Taurus, Circle Typhoon, Threat Group-3390, DEV-0322, APT6, IODINE, Hippo, BOWSER, Wekby2, UNC215
- First seen
- 2010-01-01 00:00:00
- Origin
- CN
- Primary motivation
- espionage
- Sophistication
- advanced
- Resource level
- government
- Actor type
- Espionage
- Related IoCs
- 40 (39 malicious)
- Last IoC activity
- 2026-08-27 00:00:27
- Profile updated
- 2026-07-07 12:31:09
Targeted industries: defense-and-aerospace government-and-public-sector technology-and-telecommunications energy-and-utilities manufacturing
Targeted regions: country_code:us country_code:gb country_code:jp country_code:de country_code:in
Context
Threat Group-3390 is a Chinese threat group that has extensively used strategic Web compromises to target victims. The group has been active since at least 2010 and has targeted organizations in the aerospace, government, defense, technology, energy, manufacturing and gambling/betting sectors.
Recent IoC activity
39 malicious indicators in Maltiverse are attributed to Threat Group-3390 (G0027). The 20 most recently updated:
Detection coverage
- 184 YARA rules
- 816 Sigma rules
Malware & tools used
- Exploitation for Privilege Escalation (attack-pattern)
- Data Transfer Size Limits (attack-pattern)
- Exploit Public-Facing Application (attack-pattern)
- Network Service Discovery (attack-pattern)
- At (attack-pattern)
- Process Hollowing (attack-pattern)
- Local Data Staging (attack-pattern)
- Exploitation for Client Execution (attack-pattern)
- Exfiltration to Cloud Storage (attack-pattern)
- LSASS Memory (attack-pattern)
- Windows Command Shell (attack-pattern)
- Password Managers (attack-pattern)
- Spearphishing Attachment (attack-pattern)
- Query Registry (attack-pattern)
- LSA Secrets (attack-pattern)
- Compression (attack-pattern)
- Malicious File (attack-pattern)
- System Owner/User Discovery (attack-pattern)
- Upload Malware (attack-pattern)
- Web Shell (attack-pattern)
- Registry Run Keys / Startup Folder (attack-pattern)
- Encrypted/Encoded File (attack-pattern)
- Windows Service (attack-pattern)
- Trusted Relationship (attack-pattern)
- System Network Configuration Discovery (attack-pattern)
Reports & references
- Mandiant — Apt Groups (report)
- cloud.google.com — Updated Cyber Threat Actor Naming System (report)
- i.blackhat.com — As 22 Li To Loot Or Not To Loot That Is Not A Question (report)
- web.archive.org — 330401 (report)
- labs.bitdefender.com — Operation Pzchao A Possible Return Of The Iron Tiger Apt (report)
- bitdefender.com — Bitdefender Business 2017 Whitepaper Pzchao Crea2452 En En Genericuse (report)
- cfr.org — Iron Tiger (report)
- bleepingcomputer.com — Chinese Cyber Espionage Group Hacked Government Data Center (report)
- secureworks.com — Bronze Union (report)
- Trend Micro — Operation Iron Tiger Attackers Shift East Asia United States (report)
- secureworks.com — Threat Group 3390 Targets Organizations For Cyberespionage (report)
- threatconnect.com — Threatconnect Discovers Chinese Apt Activity In Europe (report)
- nccgroup.trust — Decoding Network Data From A Gh0St Rat Variant (report)
- Kaspersky — 87914 (report)
- paper.seebug.org — Operation%20Iron%20Tiger%20Appendix (report)
- arstechnica.com — Newly Discovered Chinese Hacking Group Hacked 100 Websites To Use As Watering Holes (report)
- Kaspersky — 86083 (report)
- MITRE ATT&CK — G0027 (report)
- secureworks.com — Bronze Union (report)
- Palo Alto Unit 42 — Iron Taurus (report)
- pwc.co.uk — Pwc Cyber Threats 2020 A Year In Retrospect (report)
- ESET — Exchange Servers Under Siege 10 Apt Groups (report)
- Trend Micro — Iron Tiger Apt Updates Toolkit With Evolved Sysupdate Malware Va (report)
- raw.githubusercontent.com — Microsoftmapping (report)
- Microsoft — Microsoft Threat Actor Naming (report)
External references
- mitre-attack — G0027
- Threat Group-3390
- TG-3390
- Emissary Panda
- Iron Tiger
- Linen Typhoon
- APT27
- LuckyMouse
- BRONZE UNION
- Earth Smilodon
- SecureWorks BRONZE UNION June 2017
- Dell TG-3390
- Unit42 Emissary Panda May 2019
- Gallagher 2015
- Hacker News LuckyMouse June 2018
- Securelist LuckyMouse June 2018
- Trend Micro Iron Tiger April 2021
- Trend Micro DRBControl February 2020
- Microsoft Naming Conventions Frequently Updated
- Nccgroup Emissary Panda May 2018