G0027

G0027Threat Group-3390

Description

[Threat Group-3390](https://attack.mitre.org/groups/G0027) is a Chinese threat group that has extensively used strategic Web compromises to target victims.(Citation: Dell TG-3390) The group has been active since at least 2010 and has targeted organizations in the aerospace, government, defense, technology, energy, manufacturing and gambling/betting sectors.(Citation: SecureWorks BRONZE UNION June 2017)(Citation: Securelist LuckyMouse June 2018)(Citation: Trend Micro DRBControl February 2020)

References

  1. https://attack.mitre.org/groups/G0027
  2. https://www.secureworks.com/research/bronze-union
  3. https://www.secureworks.com/research/threat-group-3390-targets-organizations-for-cyberespionage
  4. https://unit42.paloaltonetworks.com/emissary-panda-attacks-middle-east-government-sharepoint-servers/
  5. http://arstechnica.com/security/2015/08/newly-discovered-chinese-hacking-group-hacked-100-websites-to-use-as-watering-holes/
  6. https://thehackernews.com/2018/06/chinese-watering-hole-attack.html
  7. https://securelist.com/luckymouse-hits-national-data-center/86083/
  8. https://www.trendmicro.com/en_us/research/21/d/iron-tiger-apt-updates-toolkit-with-evolved-sysupdate-malware-va.html
  9. https://documents.trendmicro.com/assets/white_papers/wp-uncovering-DRBcontrol.pdf
  10. https://research.nccgroup.com/2018/05/18/emissary-panda-a-potential-new-malicious-tool/

Software attributed to this6

TypeTargetConfidenceTier
SoftwareHyperBros0398100%live
SoftwareOwaAuths0072100%live
SoftwareClamblings066095%live
SoftwarePandoras066495%live
SoftwareSysUpdates066395%live
SoftwareASPXSpys007395%live

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

Group
APT17
Actor
APT27
Group
Suckfly
Group
APT30
Group
Threat Group-1314
Group
TA551
Sourced from MITRE ATT&CK Enterprise 14.1. Curated by Adam Lundqvist, SQUR.