Clankerusecase
Threat-actor profile
← Back to main site
Home/ Threat Actors/ Threat Group-3390

🇨🇳Threat Group-3390

🇨🇳 Threat Group-3390 is a tracked threat actor in the Clankerusecase corpus. CN-aligned. Primary motivation: State. We map 14 detection use cases to this actor across 57 MITRE ATT&CK techniques, with 0 threat-intel articles citing them.

View full actor card → All threat actors MITRE ATT&CK group spec (G0027) ↗
14Use cases
0Articles
57Techniques
0IOCs

About this actor (MITRE)

[Threat Group-3390](https://attack.mitre.org/groups/G0027) is a Chinese threat group that has extensively used strategic Web compromises to target victims.(Citation: Dell TG-3390) The group has been active since at least 2010 and has targeted organizations in the aerospace, government, defense, technology, energy, manufacturing and gambling/betting sectors.(Citation: SecureWorks BRONZE UNION June 2017)(Citation: Securelist LuckyMouse June 2018)(Citation: Trend Micro DRBControl February 2020)

Known aliases

Threat Group-3390Earth SmilodonTG-3390Emissary PandaBRONZE UNIONAPT27Iron TigerLuckyMouseLinen Typhoon

Top techniques

All other tracked techniques

T1005 · Data from Local SystemT1012 · Query RegistryT1016 · System Network Configuration DiscoveryT1018 · Remote System DiscoveryT1021.006 · Windows Remote ManagementT1027.002 · Software PackingT1027.013 · Encrypted/Encoded FileT1027.015 · CompressionT1030 · Data Transfer Size LimitsT1033 · System Owner/User DiscoveryT1046 · Network Service DiscoveryT1047 · Windows Management InstrumentationT1049 · System Network Connections DiscoveryT1053.002 · AtT1055.012 · Process HollowingT1056.001 · KeyloggingT1059.001 · PowerShellT1059.003 · Windows Command ShellT1068 · Exploitation for Privilege EscalationT1070.004 · File DeletionT1070.005 · Network Share Connection RemovalT1071.001 · Web ProtocolsT1074.001 · Local Data StagingT1074.002 · Remote Data StagingT1078 · Valid AccountsT1087.001 · Local AccountT1105 · Ingress Tool TransferT1112 · Modify RegistryT1119 · Automated CollectionT1133 · External Remote ServicesT1140 · Deobfuscate/Decode Files or InformationT1189 · Drive-by CompromiseT1190 · Exploit Public-Facing ApplicationT1195.002 · Compromise Software Supply ChainT1199 · Trusted RelationshipT1203 · Exploitation for Client ExecutionT1204.002 · Malicious FileT1210 · Exploitation of Remote ServicesT1505.003 · Web ShellT1543.003 · Windows ServiceT1547.001 · Registry Run Keys / Startup FolderT1548.002 · Bypass User Account ControlT1555.005 · Password ManagersT1560.002 · Archive via LibraryT1566.001 · Spearphishing AttachmentT1567.002 · Exfiltration to Cloud StorageT1574.001 · DLLT1583.001 · DomainsT1588.002 · ToolT1588.003 · Code Signing CertificatesT1608.001 · Upload MalwareT1608.002 · Upload ToolT1608.004 · Drive-by TargetT1685.001 · Disable or Modify Windows Event Log

Detection use cases (14)

TG-3390 / Emissary Panda DLL side-loading via signed third-party binary dropping HyperBro/PlugX AI · profile SΣ TG-3390 China Chopper / ASPXSpy webshell — IIS/Exchange w3wp.exe spawning recon & credential-access binaries AI · profile SΣ 1Password impossible-travel sign-in MITRE match Auth-Bypass on Public-Facing Service → Post-Exploit Action on Same Host (≤10 min) MITRE match Brand-Impersonation Domain Fetch Followed by User-Context Loader Within 10 Minutes MITRE match Cross-Platform ClickFix Paste-to-Pipe Loader (UI-Parent Shell with Decode-and-Execute Payload) MITRE match Developer package install spawning script-host with non-registry C2 within 5 minutes MITRE match Developer/Data-tooling Daemon Spawns Shell Child Seconds After POST to Runner/Exec Endpoint MITRE match Edge-service post-exploitation chain: internet-facing daemon → child shell or token redemption within 10 min of external request MITRE match Internet-Facing Service Process Spawning Unix Shell or Ingress-Tool LOLBin (Edge Zero-Day Post-Exploit) MITRE match Internet-facing service process spawns shell/LOLBin within minutes of public inbound connection — post-RCE command execution MITRE match Language-runtime server (node/python/java) spawns OS shell shortly after inbound request — eval / sandbox-escape exploitation chain MITRE match Linux LPE chain — anomalous algif_aead/esp4/esp6/rxrpc kernel-module load followed by same-user root transition MITRE match Low-Code / AI Workflow Runtime Sandbox-Escape — Server Process Spawns Shell + Public Egress MITRE match