FORENSIA

THREAT_ACTOR · G0027

Threat Group-3390

Also known as: Threat Group-3390, Earth Smilodon, TG-3390, Emissary Panda, BRONZE UNION, APT27, Iron Tiger, LuckyMouse, Linen Typhoon

Profile

Threat Group-3390 is a Chinese threat group that has extensively used strategic Web compromises to target victims. The group has been active since at least 2010 and has targeted organizations in the aerospace, government, defense, technology, energy, manufacturing and gambling/betting sectors.

MITRE ATT&CK ↗

Techniques

57 ATT&CK techniques attributed to this actor.

T1003.001 LSASS MemoryT1003.002 Security Account ManagerT1003.004 LSA SecretsT1005 Data from Local SystemT1012 Query RegistryT1016 System Network Configuration DiscoveryT1018 Remote System DiscoveryT1021.006 Windows Remote ManagementT1027.002 Software PackingT1027.013 Encrypted/Encoded FileT1027.015 CompressionT1030 Data Transfer Size LimitsT1033 System Owner/User DiscoveryT1046 Network Service DiscoveryT1047 Windows Management InstrumentationT1049 System Network Connections DiscoveryT1053.002 AtT1055.012 Process HollowingT1056.001 KeyloggingT1059.001 PowerShellT1059.003 Windows Command ShellT1068 Exploitation for Privilege EscalationT1070.004 File DeletionT1070.005 Network Share Connection RemovalT1071.001 Web ProtocolsT1074.001 Local Data StagingT1074.002 Remote Data StagingT1078 Valid AccountsT1087.001 Local AccountT1105 Ingress Tool TransferT1112 Modify RegistryT1119 Automated CollectionT1133 External Remote ServicesT1140 Deobfuscate/Decode Files or InformationT1189 Drive-by CompromiseT1190 Exploit Public-Facing ApplicationT1195.002 Compromise Software Supply ChainT1199 Trusted RelationshipT1203 Exploitation for Client ExecutionT1204.002 Malicious FileT1210 Exploitation of Remote ServicesT1505.003 Web ShellT1543.003 Windows ServiceT1547.001 Registry Run Keys / Startup FolderT1548.002 Bypass User Account ControlT1555.005 Password ManagersT1560.002 Archive via LibraryT1566.001 Spearphishing AttachmentT1567.002 Exfiltration to Cloud StorageT1574.001 DLLT1583.001 DomainsT1588.002 ToolT1588.003 Code Signing CertificatesT1608.001 Upload MalwareT1608.002 Upload ToolT1608.004 Drive-by TargetT1685.001 Disable or Modify Windows Event Log

Software

24 malware/tools attributed to this actor.

MimikatzWindows Credential EditorpwdumpgsecdumpPlugXChina Choppergh0st RATNetTasklistHTTPBrowserASPXSpySysteminfoipconfignetstatCobalt StrikecertutilImpacketHyperBroZxShellNBTscanClamblingRCSessionSysUpdatePandora

Related corpus activity

10,350 indicators EXHIBIT techniques this actor uses. This is a shared-technique signal, not a first-party attribution to Threat Group-3390.

IndicatorTypeFamilySevSrc
cve-2023-44976cveransomware852
cve-2026-1969cve851
cve-2025-11837cve852
cve-2026-3102cve853
cve-2026-4368cveransomware851
cve-2021-29441cve851
cve-2025-0921cve852
cve-2013-3307cve852
cve-2025-34054cve854
cve-2014-2321cve851
cve-2020-22653cve852
cve-2025-34117cve851
cve-2017-18377cve851
cve-2021-25646cve851
cve-2016-5681cve852
cve-2025-66478cve852
cve-2026-22584cve852
cve-2021-27076cve851
cve-2025-68670cve852
cve-2016-15047cve854
cve-2024-1781cve851
cve-2018-8007cve851
cve-2021-4045cve851
cve-2020-17456cve851
cve-2020-22658cve852
cve-2025-2492cve852
cve-2022-47945cve851
cve-2025-23304cve852
cve-2013-7471cve851
cve-2026-0740cve851

Showing the top 30 by severity of 10,350.