All actors

Threat Group-3390

Also reported as TG-3390, Linen Typhoon, Earth Smilodon, APT27, Iron Tiger and 27 other names. Linked to China by four sources.

Reports
511
Last reported
Known CVEs
388
Techniques in ATT&CK
57
Origin
China
ID
G0027
Merge evidence
64 alias matches

Reports per quarter

  1. 2011 Q2: 1 report
  2. 2011 Q3: no reports
  3. 2011 Q4: 1 report
  4. 2012 Q1: no reports
  5. 2012 Q2: no reports
  6. 2012 Q3: no reports
  7. 2012 Q4: 1 report
  8. 2013 Q1: 1 report
  9. 2013 Q2: no reports
  10. 2013 Q3: 1 report
  11. 2013 Q4: no reports
  12. 2014 Q1: 3 reports
  13. 2014 Q2: no reports
  14. 2014 Q3: 2 reports
  15. 2014 Q4: 1 report
  16. 2015 Q1: 1 report
  17. 2015 Q2: no reports
  18. 2015 Q3: 7 reports
  19. 2015 Q4: 4 reports
  20. 2016 Q1: 1 report
  21. 2016 Q2: 3 reports
  22. 2016 Q3: 1 report
  23. 2016 Q4: 2 reports
  24. 2017 Q1: 6 reports
  25. 2017 Q2: 5 reports
  26. 2017 Q3: 1 report
  27. 2017 Q4: 5 reports
  28. 2018 Q1: 8 reports
  29. 2018 Q2: 10 reports
  30. 2018 Q3: 8 reports
  31. 2018 Q4: 3 reports
  32. 2019 Q1: 8 reports
  33. 2019 Q2: 13 reports
  34. 2019 Q3: 15 reports
  35. 2019 Q4: 14 reports
  36. 2020 Q1: 21 reports
  37. 2020 Q2: 20 reports
  38. 2020 Q3: 15 reports
  39. 2020 Q4: 16 reports
  40. 2021 Q1: 36 reports
  41. 2021 Q2: 34 reports
  42. 2021 Q3: 21 reports
  43. 2021 Q4: 17 reports
  44. 2022 Q1: 27 reports
  45. 2022 Q2: 23 reports
  46. 2022 Q3: 19 reports
  47. 2022 Q4: 10 reports
  48. 2023 Q1: 15 reports
  49. 2023 Q2: 7 reports
  50. 2023 Q3: 7 reports
  51. 2023 Q4: 4 reports
  52. 2024 Q1: 5 reports
  53. 2024 Q2: 6 reports
  54. 2024 Q3: 6 reports
  55. 2024 Q4: 1 report
  56. 2025 Q1: 9 reports
  57. 2025 Q2: 4 reports
  58. 2025 Q3: 5 reports
  59. 2025 Q4: 4 reports
  60. 2026 Q1: 4 reports
  61. 2026 Q2: 46 reports
  62. 2026 Q3: 3 reports
Dated reports, 2011 Q2 to 2026 Q3.

Techniques seen in the last two years

Show all 139 techniques Show fewer

Counts come from technique IDs in the actor's report text. “Reports only” means reports name the technique but MITRE ATT&CK® does not list it for this actor.

Also listed by ATT&CK

Show all 15 techniques Show fewer

CVEs named in reports

Show all 388 CVEs Show fewer

KEV marks a CVE in CISA's Known Exploited Vulnerabilities Catalog, and “ransomware” marks one that the catalog records as used in ransomware campaigns.

Reports

  1. Bankshot (Malware Family)

    date ORKL added it fromORKL

  2. StoneDrill (Malware Family)

    date ORKL added it fromORKL

Show all 511 reports Show fewer
  1. Ghost RAT (Malware Family)

    date ORKL added it fromORKL

  2. Oblique RAT (Malware Family)

    date ORKL added it fromORKL

  3. METALJACK (Malware Family)

    date ORKL added it fromORKL

  4. elf.wellmess (Malware Family)

    date ORKL added it fromORKL

  5. SUNBURST (Malware Family)

    date ORKL added it fromORKL

  6. CHINACHOPPER (Malware Family)

    date ORKL added it fromORKL

  7. Emissary Panda, APT 27, LuckyMouse, Bronze Union

    date ORKL added it fromORKL

  8. Threat Group Cards: A Threat Actor Encyclopedia

    date ORKL added it fromORKL

  9. HyperBro (Malware Family)

    date ORKL added it fromORKL

  10. MimiKatz (Malware Family)

    date ORKL added it fromORKL

  11. TwoFace (Malware Family)

    date ORKL added it fromORKL

  12. ZXShell (Malware Family)

    date ORKL added it fromORKL

  13. PlugX (Malware Family)

    date ORKL added it fromORKL

  14. PowGoop (Malware Family)

    date ORKL added it fromORKL

  15. Threat Group Cards: A Threat Actor Encyclopedia

    date ORKL added it fromORKL

  16. Emissary Panda, APT 27, LuckyMouse, Bronze Union

    date ORKL added it fromORKL

  17. Dragons in Thunder

    Malpedia library date fromORKL

  18. Modern Asia APT groups TTPs

    file creation date Kaspersky fromORKL

  19. Iron Tiger’s SysUpdate Reappears, Adds Linux Targeting

    date in the title fromORKL

  20. Iron Tiger's SysUpdate Reappears, Adds Linux Targeting

    file creation date Trendmicro fromORKL

  21. The Mac Malware of 2022

    date in the title fromORKL

  22. Threat Analysis Report- PlugX RAT Loader Evolution

    date in the title fromORKL

  23. LuckyMouse uses a backdoored Electron app to target MacOS

    date in the title fromORKL

  24. LuckyMouse uses a backdoored Electron app to target MacOS - SEKOIA.IO Blog

    date in the CCS '25 data SEKOIA fromORKLCCS '25 data

  25. Iron Tiger Compromises Chat Application Mimi, Targets Windows, Mac, and Linux Users

    date in the CCS '25 data Trend Micro fromORKLCCS '25 data

  26. Advanced Persistent Threats (APTs)

    date in the title fromORKL

  27. PowerPoint Presentation

    Malpedia library date Hughes, Jennifer fromORKLCCS '25 data

  28. APT_trends_report_Q2_2022_Securelist

    file creation date fromORKL

  29. yir-cyber-threats-annex-download.pdf

    Malpedia library date fromORKL

  30. SockDetour Backdoor Targets U.S. Defense Contractors

    date in the CCS '25 data palo alto networks fromORKLCCS '25 data

  31. APT27 Group Targets German Organizations with HyperBro

    date in the title fromORKL

  32. BfV Cyber-Brief Nr. 01/2022

    date in the CCS '25 data BfV fromCCS '25 data

  33. GhostEmperor- From ProxyLogon to kernel mode

    date in the title fromORKL

  34. Advanced Persistent Threats (APTs)

    date in the title fromORKL

  35. eset_threat_report_t12021

    file creation date fromORKL

  36. Mustang Panda PlugX - 45.251.240.55 Pivot

    Malpedia library date fromORKL

  37. APT Threat Landscape of Taiwan in 2020

    date in the title fromORKL

  38. APT_trends_report_Q1_2021_Securelist

    file creation date fromORKL

  39. APT trends report Q1 2021

    date in the title fromORKL

  40. Iron Tiger APT Updates Toolkit With Evolved SysUpdate Malware

    date in the CCS '25 data SecureWorks fromORKLCCS '25 data

  41. The leap of a Cycldek-related threat actor

    date in the title fromORKL

  42. Exchange servers under siege from at least 10 APT groups

    date in the title fromORKL

  43. APT27+turns+to+ransomware

    Malpedia library date Kaspersky fromORKLCCS '25 data

  44. China's APT hackers move to ransomware attacks

    date in the title fromORKL

  45. China cyber attacks- the current threat landscape

    date in the title fromORKL

  46. Operation StealthyTrident- corporate software under attack

    date in the title fromORKL

  47. APT Group Targeting Governmental Agencies in East Asia

    date in the title fromORKL

  48. Investigation with a twist_ an accidental APT attack and averted data destruction

    date in the CCS '25 data Positive Technologies fromORKLCCS '25 data

  49. Group-IB_Hi-Tech_Crime_Trends_2020-2021_en

    file creation date fromORKL

  50. What even is Winnti-

    date in the title fromORKL

  51. BRONZE VINEWOOD Targets Supply Chains _ Secureworks

    date in the CCS '25 data SecureWorks fromORKLCCS '25 data

  52. BRONZE VINEWOOD Targets Supply Chains

    date in the title fromORKL

  53. Deep-dive: The DarkHotel APT

    Malpedia library date Bushido Token fromORKLCCS '25 data

  54. WastedLoader or DridexLoader-

    date in the title fromORKL

  55. T1055 Process Injection

    date in the title fromORKL

  56. What happened between the BigBadWolf and the Tiger-

    date in the title fromORKL

  57. WINNTI GROUP_ Insights From the Past

    date in the CCS '25 data QuoIntelligence fromORKLCCS '25 data

  58. WINNTI GROUP- Insights From the Past

    date in the title fromORKL

  59. report-bb-decade-of-the-rats

    file creation date fromORKL

  60. Is APT 27 Abusing COVID-19 To Attack People -!

    date in the title fromORKL

  61. Is APT 27 Abusing COVID-19 To Attack People !

    date in the CCS '25 data Yoroi fromCCS '25 data

  62. cybersecurity-threatscape-2019-q4-eng

    file creation date fromORKL

  63. New Variant of TrickBot Being Spread by Word Document

    date in the title fromORKL

  64. APT27 ZXShell RootKit module updates

    date in the CCS '25 data Lab52 fromORKLCCS '25 data

  65. APT27 ZxShell RootKit module updates

    date in the title fromORKL

  66. cybersecurity-threatscape-2019-q3-eng

    file creation date fromORKL

  67. APT Trends Report Q2 2018

    file creation date Kaspersky fromORKL

  68. Analytics

    Malpedia library date Positive Technologies fromORKLCCS '25 data

  69. BLOG SERIES_Huge Fan of Your Work

    date in the CCS '25 data Crowdstrike fromORKLCCS '25 data

  70. Emissary Panda APT- Recent infrastructure and RAT analysis

    date in the title fromORKL

  71. A Peek into BRONZE UNION's Toolbox

    file creation date Dell Secureworks fromORKL

  72. Analytics

    Malpedia library date fromORKL

  73. Operation-Taskmasters-2019-eng

    date in the CCS '25 data Positive Technologies fromORKLCCS '25 data

  74. Emissary Panda DLL Backdoor

    date in the title fromORKL

  75. Operation Soft Cell_ A Worldwide Campaign Against Telecommunications Providers

    date in the CCS '25 data Cybereason fromORKLCCS '25 data

  76. Possible Turla HTTP Listener

    date in the title fromORKL

  77. Into the Fog - The Return of ICEFOG APT

    Malpedia library date fromORKL

  78. Emissary Panda Attacks Middle East Government Sharepoint Servers

    date in the CCS '25 data Palo Alto fromORKLCCS '25 data

  79. APT_trends_report_Q1_2019_Securelist

    file creation date fromORKL

  80. A Peek into BRONZE UNION’s Toolbox

    date in the title fromORKL

  81. A Peek into BRONZE UNION’s Toolbox

    date in the CCS '25 data SecureWorks fromORKLCCS '25 data

  82. 2018 Master Table

    file creation date fromORKL

  83. ENISA Threat Landscape Report 2018

    file creation date fromORKL

  84. CTA Adversary Playbook- Goblin Panda

    date in the title fromORKL

  85. LuckyMouse signs malicious NDISProxy driver with certificate of Chinese IT company

    date in the CCS '25 data Kaspersky fromORKLCCS '25 data

  86. APT Trends Report Q2 2018

    date in the title fromORKL

  87. Decoding network data from a Gh0st RAT variant

    date in the title fromORKL

  88. Decoding network data from a Gh0st RAT variant

    date in the CCS '25 data Bitdefender fromORKLCCS '25 data

  89. Operation PZChao- a possible return of the Iron Tiger APT

    date in the title fromORKL

  90. Bitdefender Labs

    Malpedia library date Bitdefender fromORKLCCS '25 data

  91. Advanced Persistent Threat Groups

    date in the title fromORKL

  92. BRONZE UNION Cyberespionage Persists Despite Disclosures

    date in the title fromORKL

  93. DragonOK Updates Toolset and Targets Multiple Geographic Regions

    date in the CCS '25 data Palo Alto Networks fromORKLCCS '25 data

  94. A Tale of Two Targets

    date in the title fromORKL

  95. threatconnect-discovers-chinese-apt-activity-in-europe

    date in the CCS '25 data ThreatConnect fromORKLCCS '25 data

  96. security_report_20160613.pdf

    Malpedia library date fromORKL

  97. Zscaler Research: Malicious Office files dropping Kasidet and Dridex

    date in the CCS '25 data Zscaler fromORKLCCS '25 data

  98. Threat Group-3390 Targets Organizations For Cyberespionage

    file creation date Dell Secureworks fromORKL

  99. Reversing the C2C HTTP Emmental communication

    date in the title fromORKL

  100. Operation Iron Tiger Appendix

    Malpedia library date Trend Micro fromORKLCCS '25 data

  101. Threat Group 3390 Cyberespionage

    date in the title fromORKL

  102. Uncovering the Seven Pointed Dagger

    Malpedia library date Arbor Networks fromORKLCCS '25 data

  103. Disect Android APKs like a Pro - Static code analysis

    date in the title fromORKL

  104. Iran and Russia blamed for state-sponsored espionage

    date in the title fromORKL

  105. Iran and Russia blamed for statesponsored espionage

    Malpedia library date fromORKL

  106. Iran and Russia blamed for state-sponsored espionage

    Malpedia library date fromORKL

  107. Alleged Apt Intrusion Set: 1.Php Group

    file creation date Zscaler, ThreatLabz fromORKL

  108. Inside a Back Door Attack

    Malpedia library date fromORKL

Newest first. Details opens the report in Explore.