Gold Open Source
ExplorePackagesVulnerabilitiesCWEsMCP ServersScan
Login
Gold Open Source

The authoritative source for production-ready open-source components. Every package, container image, AI model, and MCP server undergoes rigorous verification for security, malware, and license compliance.

Explore Gold

  • Explore Everything
  • Packages
  • Gold Certified Packages
  • Container Images
  • AI Models
  • MCP Servers
  • Agent Skills
  • Chip Manufacturers

Security Data & Tools

  • Scan Your Dependencies
  • Trending Threats
  • Threat RSS Feeds
  • CVE Database
  • Actively Exploited (KEV)
  • SGZ Zero-Days
  • CWE Index
  • MITRE ATT&CK
  • Malicious Packages
  • Security Glossary
  • Supply-Chain Report
  • Developers (API & Badge)
  • Chrome Extension
  • Credits & Data Sources

Products

  • The Platform
  • ESSCM
  • Portal
  • TPRM
  • OSM
  • Cowork
  • Code / Runner
  • Guard

Use Cases

  • Know Your Software
  • Auto-Fix Vulnerabilities
  • Asset Discovery
  • AI Governance
  • MCP Server Security
  • Supply Chain Compliance
  • Zero-Day Discovery
  • All Use Cases

Company

  • About
  • Pricing
  • Blog
  • Documentation
  • Safeguard Academy
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 Gold Open Source. All rights reserved.

Built with care bySafeguard
Home/ATT&CK/Groups/G0027
MITRE ATT&CK Group

Threat Group-3390 (G0027)

Earth SmilodonTG-3390Emissary PandaBRONZE UNIONAPT27Iron TigerLuckyMouseLinen Typhoon
ShareXLinkedInRedditHN

[Threat Group-3390](https://attack.mitre.org/groups/G0027) is a Chinese threat group that has extensively used strategic Web compromises to target victims.(Citation: Dell TG-3390) The group has been active since at least 2010 and has targeted organizations in the aerospace, government, defense, technology, energy, manufacturing and gambling/betting sectors.(Citation: SecureWorks BRONZE UNION June 2017)(Citation: Securelist LuckyMouse June 2018)(Citation: Trend Micro DRBControl February 2020)

▪Techniques used (57)

T1068Exploitation for Privilege EscalationT1030Data Transfer Size LimitsT1190Exploit Public-Facing ApplicationT1046Network Service DiscoveryT1053.002AtT1055.012Process HollowingT1074.001Local Data StagingT1203Exploitation for Client ExecutionT1567.002Exfiltration to Cloud StorageT1003.001LSASS MemoryT1059.003Windows Command ShellT1555.005Password ManagersT1566.001Spearphishing AttachmentT1012Query RegistryT1003.004LSA SecretsT1027.015CompressionT1204.002Malicious FileT1033System Owner/User DiscoveryT1608.001Upload MalwareT1505.003Web ShellT1547.001Registry Run Keys / Startup FolderT1027.013Encrypted/Encoded FileT1543.003Windows ServiceT1199Trusted RelationshipT1016System Network Configuration DiscoveryT1105Ingress Tool TransferT1056.001KeyloggingT1059.001PowerShellT1078Valid AccountsT1608.004Drive-by TargetT1588.002ToolT1018Remote System DiscoveryT1583.001DomainsT1189Drive-by CompromiseT1140Deobfuscate/Decode Files or InformationT1003.002Security Account ManagerT1133External Remote ServicesT1005Data from Local SystemT1087.001Local AccountT1195.002Compromise Software Supply ChainT1548.002Bypass User Account ControlT1119Automated CollectionT1560.002Archive via LibraryT1027.002Software PackingT1588.003Code Signing CertificatesT1047Windows Management InstrumentationT1071.001Web ProtocolsT1070.005Network Share Connection RemovalT1021.006Windows Remote ManagementT1574.001DLLT1070.004File DeletionT1685.001Disable or Modify Windows Event LogT1608.002Upload ToolT1112Modify RegistryT1210Exploitation of Remote ServicesT1074.002Remote Data StagingT1049System Network Connections Discovery

▪Software used (24)

S0039NettoolS0096SysteminfotoolS0008gsecdumptoolS0013PlugXmalwareS0073ASPXSpymalwareS0154Cobalt StrikemalwareS0002MimikatztoolS0357ImpackettoolS0032gh0st RATmalwareS0160certutiltoolS0020China ChoppermalwareS0070HTTPBrowsermalwareS0057TasklisttoolS0104netstattoolS0663SysUpdatemalwareS0398HyperBromalwareS0412ZxShellmalwareS0662RCSessionmalwareS0100ipconfigtoolS0660ClamblingmalwareS0006pwdumptoolS0590NBTscantoolS0664PandoramalwareS0005Windows Credential Editortool
G0027on MITRE ATT&CK →

MITRE ATT&CK® is a registered trademark of The MITRE Corporation. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation.