Overview 291 indicators
Threat Group-3390 is a Chinese threat group that has extensively used strategic Web compromises to target victims. The group has been active since at least 2010 and has targeted organizations in the aerospace, government, defense, technology, energy, manufacturing and gambling/betting sectors.
| domain | 255 | G0027-domain.txt |
| ipv4 | 21 | G0027.json |
| url | 15 | G0027.json |
Techniques 57 ATT&CK
Open in ATT&CK Navigator → or download the layer (57 techniques, layer 4.5)
- T1003.001 LSASS Memory
- T1003.002 Security Account Manager
- T1003.004 LSA Secrets
- T1005 Data from Local System
- T1012 Query Registry
- T1016 System Network Configuration Discovery
- T1018 Remote System Discovery
- T1021.006 Windows Remote Management
- T1027.002 Software Packing
- T1027.013 Encrypted/Encoded File
- T1027.015 Compression
- T1030 Data Transfer Size Limits
- T1033 System Owner/User Discovery
- T1046 Network Service Discovery
- T1047 Windows Management Instrumentation
- T1049 System Network Connections Discovery
- T1053.002 At
- T1055.012 Process Hollowing
- T1056.001 Keylogging
- T1059.001 PowerShell
- T1059.003 Windows Command Shell
- T1068 Exploitation for Privilege Escalation
- T1070.004 File Deletion
- T1070.005 Network Share Connection Removal
- T1071.001 Web Protocols
- T1074.001 Local Data Staging
- T1074.002 Remote Data Staging
- T1078 Valid Accounts
- T1087.001 Local Account
- T1105 Ingress Tool Transfer
- T1112 Modify Registry
- T1119 Automated Collection
- T1133 External Remote Services
- T1140 Deobfuscate/Decode Files or Information
- T1189 Drive-by Compromise
- T1190 Exploit Public-Facing Application
- T1195.002 Compromise Software Supply Chain
- T1199 Trusted Relationship
- T1203 Exploitation for Client Execution
- T1204.002 Malicious File
- T1210 Exploitation of Remote Services
- T1505.003 Web Shell
- T1543.003 Windows Service
- T1547.001 Registry Run Keys / Startup Folder
- T1548.002 Bypass User Account Control
- T1555.005 Password Managers
- T1560.002 Archive via Library
- T1566.001 Spearphishing Attachment
- T1567.002 Exfiltration to Cloud Storage
- T1574.001 DLL
- T1583.001 Domains
- T1588.002 Tool
- T1588.003 Code Signing Certificates
- T1608.001 Upload Malware
- T1608.002 Upload Tool
- T1608.004 Drive-by Target
- T1685.001 Disable or Modify Windows Event Log
Software 24
- Mimikatz
- Windows Credential Editor
- pwdump
- gsecdump
- PlugX
- China Chopper
- gh0st RAT
- Net
- Tasklist
- HTTPBrowser
- ASPXSpy
- Systeminfo
- ipconfig
- netstat
- Cobalt Strike
- certutil
- Impacket
- HyperBro
- ZxShell
- NBTscan
- Clambling
- RCSession
- SysUpdate
- Pandora
Principal sources 70 reports
Ranked by how many of this actor's indicators each report brought in.
- 77secureworks.com/cyber-threat-intelligence/threats/threa…
- 64twitter.com/_marklech_/status/1268138088167018498
- 64securelist.com/cycldek-bridging-the-air-gap/97157
- 20twitter.com/BushidoToken/status/1577605361930063876
- 20trendmicro.com/en_us/research/22/h/irontiger-compromis…
- 20trendmicro.com/content/dam/trendmicro/global/en/resear…
- 20virustotal.com/graph/embed/gdc80667c54cc46cba1038b34ef…
- 20virustotal.com/gui/file/07aa739fa4942cfd68d4a075568456…
Related groups 12
What the sources have in common — not a claim that these are the same actor. See the whole graph.
4 more in the relationship graph.
Timeline 291 indicators
Each entry is a batch of indicators that appeared upstream on one date, under the report it was filed with.
No indicator matches. Only the most recent 300 are on this page — the rest are in the JSON.
-
x.com/skocherhan/status/1942043295292481785
103.243.26.213:8000 -
x.com/TuringAlex/status/1977626210609049683 · trendmicro.com/en_us/research/22/l/probing-weaponized-… · virustotal.com/gui/ip-address/8.219.76.37/relations · virustotal.com/gui/file/db4497090a94d0189aa3c3f4fcee30… · otx.alienvault.com/pulse/6399f1943fb578ccb093a7b7
unix.s3amazonbucket.com -
blog.eclecticiq.com/chinese-state-sponsored-cyber-espionage… · virustotal.com/gui/file/ce226bd1f53819d6654caf04a7bb41… · virustotal.com/gui/file/29741e60dca8a68021be35525a6b46… · virustotal.com/gui/file/7201e604359019b484f6a6ac4d8cba… · virustotal.com/gui/file/6e3c3045bb9d0db4817ad0441ee3c9… · virustotal.com/gui/file/3443bb895444c1c7fa0beab54f93a7…
http://23.224.61.12 http://45.32.33.17 -
twitter.com/felixaime/status/1698741466619838510 · virustotal.com/gui/file/12e1f50d7c9cf546c90545588bc369… · virustotal.com/gui/file/ee66ebcbe872def8373a4e5ea23f14…
ipv4 154.93.7.99:8090 ipv4 38.54.119.239:443 url http://38.54.119.239 -
cofense.com/blog/open-source-gh0st-rat-still-haunti… · otx.alienvault.com/pulse/6448506f7a10b2c157ec8fc4
api.youkesdt.asia cloudservicesdevc.tk datacache.cloudservicesdevc.tk youkesdt.asia -
trendmicro.com/en_us/research/23/c/iron-tiger-sysupdat… · otx.alienvault.com/pulse/63ff5a60ca3dccd68551ba17
88tech.me atlas-sian.net dev.gitlabs.me gitlabs.me jira.atlas-sian.net myvandyke.net oa.88tech.me oa.myvandyke.net order.myvandyke.net ybupdate.me -
blog.eclecticiq.com/chinese-state-sponsored-cyber-espionage… · virustotal.com/gui/file/ce226bd1f53819d6654caf04a7bb41… · virustotal.com/gui/file/29741e60dca8a68021be35525a6b46… · virustotal.com/gui/file/7201e604359019b484f6a6ac4d8cba… · virustotal.com/gui/file/6e3c3045bb9d0db4817ad0441ee3c9… · virustotal.com/gui/file/3443bb895444c1c7fa0beab54f93a7…
45.32.33.17:443 -
x.com/TuringAlex/status/1977626210609049683 · trendmicro.com/en_us/research/22/l/probing-weaponized-… · virustotal.com/gui/ip-address/8.219.76.37/relations · virustotal.com/gui/file/db4497090a94d0189aa3c3f4fcee30… · otx.alienvault.com/pulse/6399f1943fb578ccb093a7b7
amazonawsgarages.com analyaze.s3amazonbucket.com analysis.windowstearns.com cornm100.io files.amazonawsgarages.com livehelp100services.com livehelpl00service.com livelyhellp.chat max.cornm100.io s.livelyhellp.chat s3amazonbucket.com service.livehelpl00service.com services.livehelp100services.com -
x.com/TuringAlex/status/1977626210609049683 · trendmicro.com/en_us/research/22/l/probing-weaponized-… · virustotal.com/gui/ip-address/8.219.76.37/relations · virustotal.com/gui/file/db4497090a94d0189aa3c3f4fcee30… · otx.alienvault.com/pulse/6399f1943fb578ccb093a7b7
windowstearns.com -
twitter.com/BushidoToken/status/1577605361930063876 · trendmicro.com/en_us/research/22/h/irontiger-compromis… · trendmicro.com/content/dam/trendmicro/global/en/resear… · virustotal.com/graph/embed/gdc80667c54cc46cba1038b34ef… · virustotal.com/gui/file/07aa739fa4942cfd68d4a075568456…
domain dataanalyticsclub.com url http://104.168.236.46 -
twitter.com/BushidoToken/status/1577605361930063876 · trendmicro.com/en_us/research/22/h/irontiger-compromis… · trendmicro.com/content/dam/trendmicro/global/en/resear… · virustotal.com/graph/embed/gdc80667c54cc46cba1038b34ef… · virustotal.com/gui/file/07aa739fa4942cfd68d4a075568456…
domain center.veryssl.org domain linux.updatelive-oline.com domain ntp-server.asia domain time.ntp-server.asia domain time1.ntp-server.asia domain trust.veryssl.org domain updatelive-oline.com domain windows.updatelive-oline.com ipv4 104.168.211.246:443 ipv4 139.180.216.65:443 ipv4 45.142.214.193:443 ipv4 45.77.250.141:443 ipv4 80.92.206.158:443 url http://104.168.211.246 url http://139.180.216.65 url http://45.142.214.193 url http://45.77.250.141 url http://80.92.206.158 -
virustotal.com/gui/file/074edd82af9bbfd98dd0da167f3712…
i1mc.xyz jiqun.i1mc.xyz -
twitter.com/autumn_good_35/status/14862965696413409… · verfassungsschutz.de/SharedDocs/publikationen/DE/cyberabwehr…
103.79.77.200:443 104.168.236.46:443 87.98.190.184:443 -
virustotal.com/gui/file/051400edf4aae2a1041743c1b12740… · virustotal.com/gui/file/094f0713e788800496344035e388ef… · virustotal.com/gui/file/6784171c7bfabec50350f3a9042df8… · virustotal.com/gui/file/9dcf1501177b898785315d1f3024cd… · virustotal.com/gui/file/9f7f7b98342621e106def4e55e98fc…
buy.teamviewsoft.com support.teamviewsoft.com teamviewsoft.com -
twitter.com/JAMESWT_MHT/status/1476105632751267840 · docs.google.com/document/d/1oYX3uN6KxIX_StzTH0s0yFNNoHD…
update.fasterwall.com -
trendmicro.com/en_us/research/21/d/iron-tiger-apt-upda… · otx.alienvault.com/pulse/607094697706cc521d0f0788
domain settings-win.dyndns-office.com ipv4 35.187.148.253:443 ipv4 35.220.135.85:443 ipv4 47.75.49.32:443 ipv4 85.204.74.143:443 ipv4 89.35.178.105:443 -
securelist.com/the-leap-of-a-cycldek-related-threat-ac… · otx.alienvault.com/pulse/606dd51193fe95bf9552902e
cloud.cutepaty.com cutepaty.com giaitrinuoc.com phong.giaitrinuoc.com phongay.com static.phongay.com -
virustotal.com/gui/file/99cc8ee3a385c767e25ebaf2dcaefd…
adobesys.com -
otx.alienvault.com/pulse/5fd1090b830e4fba81b06cef
chrome-upgrade.com microlynconline.com vegispaceshop.org -
medium.com/@Sebdraven/rtf-royal-road-drops-a-new-b… · otx.alienvault.com/pulse/5f43f48c0712b9c5245d4824 · virustotal.com/gui/ip-address/91.218.113.17/relations
ckvyk.com ckvyk.net ggfnv.com jgkgv.net jkncj.com -
twitter.com/Vishnyak0v/status/1287308019336990720 (… · virustotal.com/gui/file/36fad80a5f328f487b20a3f5fc5f19… · virustotal.com/gui/file/788bd34d3c5d12b9767f8ac5587f19…
http://139.180.208.225/ajax -
twitter.com/pancak3lullz/status/1286021877375303682 · twitter.com/pancak3lullz/status/1286027620740726785 · app.any.run/tasks/949f2624-505c-4f10-a304-1671492f9… · virustotal.com/gui/file/96e38c55174bf287fe0c21a4d8fa63…
domain 265g.site domain gj.wxb2568.cn ipv4 27.124.26.136:1943 ipv4 27.124.26.136:59486 -
twitter.com/_marklech_/status/1268138088167018498 · securelist.com/cycldek-bridging-the-air-gap/97157
domain 24h.tinthethaoi.com domain cdn.laokpl.com domain chinhsech.com domain chototem.com domain conglyan.com domain cooodkord.com domain cophieu.dcsvnqvmn.com domain coreders.com domain daikynguyen21.com domain dangquanwatch.com domain dcsvnqvmn.com domain diendanlichsu.com domain dongaruou.com domain dongnain.com domain giaoxuchuson.com domain hanghoa.trenduang.com domain hcm.vietbaonam.com domain hcmuafgh.com domain images.webprogobest.com domain info.coreders.com domain khinhte.chinhsech.com domain kinhte.chototem.com domain kinhtevanhoa.com domain laokpl.com domain laomoodwin.com domain laovoanew.com domain lat.conglyan.com domain login.dangquanwatch.com domain login.diendanlichsu.com domain login.giaoxuchuson.com domain login.thanhnienthegioi.com domain login.vietnamfar.com domain luan.conglyan.com domain ministop14.com domain mychau.dongnain.com domain news.cooodkord.com domain news.trungtamwtoa.com domain nghiencuu.onetotechnologys.com domain nhantai.xmeyeugh.com domain onetotechnologys.com domain quocphong.ministop14.com domain thanhnien.vietnannnet.com domain thanhnienthegioi.com domain thegioi.kinhtevanhoa.com domain thoitiet.yrindovn.com domain thoitietdulich.com domain tinmoi.thoitietdulich.com domain tinmoi.vieclamthemde.com domain tinthethaoi.com domain tintuc.daikynguyen21.com domain toiyeuvn.dongaruou.com domain trenduang.com domain trungtamwtoa.com domain vieclamthemde.com domain vietbaonam.com domain vietnamfar.com domain vietnannnet.com domain web.laomoodwin.com domain web.laovoanew.com domain webprogobest.com domain xmeyeugh.com domain yrindovn.com url http://103.253.25.73 -
marcoramilli.com/2020/03/19/is-apt27-abusing-covid-19-to… · otx.alienvault.com/pulse/5e734d45158714422bc4e774
motivation.neighboring.site -
otx.alienvault.com/pulse/5da9dc215c51c8a86a2d19f1
chatsecure.uk.to encryptit.qc.to privatehd.us.to sex17.us.to -
twitter.com/MeltX0R/status/1179800013150527488
tdjsyqty0takah2x.gitoos.com -
twitter.com/MeltX0R/status/1175309376493629440 · meltx0r.github.io/tech/2019/09/19/emissary-panda-apt.html
awvsf7esh.dellrescue.com yofeopxuuehixwmj.redhatupdater.com -
unit42.paloaltonetworks.com/emissary-panda-attacks-middle-east-gove…
185.12.45.134:443 -
medium.com/@Sebdraven/goblin-panda-changes-the-dro…
tajikstantravel.dynamic-dns.net -
blogs.quickheal.com/apt-27-like-newcore-rat-virut-exploitin…
domain aibeichen.cn ipv4 115.214.104.26:81 url http://192.167.4.10 url http://43.242.75.228 -
medium.com/@Sebdraven/goblin-panda-continues-to-ta… · otx.alienvault.com/pulse/5ccabe9589bea41847a35a0f · twitter.com/_marklech_/status/1268138088167018498 · securelist.com/cycldek-bridging-the-air-gap/97157
web.hcmuafgh.com -
twitter.com/JAMESWT_MHT/status/1476105632751267840 · docs.google.com/document/d/1oYX3uN6KxIX_StzTH0s0yFNNoHD…
activity.maacson.com bbs.maacson.com dns.itbaydns.com fasterwall.com govmn.tk maacson.com static.fasterwall.com -
secureworks.com/research/a-peek-into-bronze-unions-tool… · twitter.com/MeltX0R/status/1175309376493629440 · meltx0r.github.io/tech/2019/09/19/emissary-panda-apt.html
language.wikaba.com solution.instanthq.com -
secureworks.com/research/a-peek-into-bronze-unions-tool…
mildupdate.com trprivates.com -
medium.com/@Sebdraven/goblin-panda-changes-the-dro…
skylineqaz.crabdance.com tele.zyns.com uzwatersource.dynamic-dns.net -
labs.bitdefender.com/wp-content/uploads/downloads/operation-…
centuriosa.info dll.pzchao.com down.pzchao.com rat.pzchao.com up.pzchao.com zll855.gicp.net zll855.no-ip.info -
otx.alienvault.com/pulse/5da9dc215c51c8a86a2d19f1
chatsecurelite.uk.to chatsecurelite.us.to -
secureworks.com/cyber-threat-intelligence/threats/threa…
american.blackcmd.com api.apigmail.com apigmail.com backup.darkhero.org bel.updatawindows.com binary.update-onlines.org blackcmd.com castle.blackcmd.com ctcb.blackcmd.com darkhero.org dav.local-test.com dev.local-test.com ftp.google-ana1ytics.com ga.blackcmd.com google-ana1ytics.com helpdesk.blackcmd.com helpdesk.csc-na.com helpdesk.hotmail-onlines.com helpdesk.lnip.org hotmail-onlines.com hotmailcontact.net jobs.hotmail-onlines.com justufogame.com laxness-lab.com lnip.org local-test.com login.hansoftupdate.com long.update-onlines.org longlong.update-onlines.org longshadow.dyndns.org longshadow.update-onlines.org longykcai.update-onlines.org lostself.update-onlines.org mac.navydocument.com mail.csc-na.com mantech.updatawindows.com micr0soft.org microsoft-outlook.org mtc.navydocument.com mtc.update-onlines.org navydocument.com news.hotmail-onlines.com oac.3322.org ocean.apigmail.com ocean.local-test.com pchomeserver.com registre.organiccrap.com security.pomsys.org services.darkhero.org sgl.updatawindows.com shadow.update-onlines.org sonoco.blackcmd.com test.local-test.com test.logmastre.com up.gtalklite.com updatawindows.com update-onlines.org update.deepsoftupdate.com update.hancominc.com update.micr0soft.org update.pchomeserver.com urs.blackcmd.com wang.darkhero.org webs.local-test.com word.apigmail.com wordpress.blackcmd.com working.blackcmd.com working.darkhero.org working.hotmail-onlines.com www.google-ana1ytics.com www.trendmicro-update.org www.update-onlines.org x.apigmail.com ykcai.update-onlines.org ykcailostself.dyndns-free.com ykcainobody.dyndns.org zj.blackcmd.com -
securelist.com/luckymouse-ndisproxy-driver/87914
http://103.75.190.28 http://213.109.87.58 -
medium.com/@Sebdraven/malicious-document-targets-v…
cat.toonganuh.com coco.sodexoa.com dn.dulichbiendao.org dulichculao.com gateway.vietbaotinmoi.com halong.dulichculao.com hn.dulichbiendao.org new.sggpnews.com toonganuh.com web.thoitietvietnam.org wouderfulu.impresstravel.ga -
medium.com/@Sebdraven/gobelin-panda-against-the-be…
36106g.com cv3sa.gicp.net sd123.eicp.net -
medium.com/@Sebdraven/gobelin-panda-against-the-be… · medium.com/@Sebdraven/rtf-royal-road-drops-a-new-b… · otx.alienvault.com/pulse/5f43f48c0712b9c5245d4824 · virustotal.com/gui/ip-address/91.218.113.17/relations
kmbk8.hicp.net -
securelist.ru/luckymouse-hits-national-data-center/90…
bbs.sonypsps.com google-updata.tk update.iaacstudio.com windows-updata.tk -
securelist.ru/luckymouse-hits-national-data-center/90… · twitter.com/JAMESWT_MHT/status/1476105632751267840 · docs.google.com/document/d/1oYX3uN6KxIX_StzTH0s0yFNNoHD…
wh0am1.itbaydns.com
Further reading 79
- arstechnica.com/security/2015/08/newly-discovered-chine…
- attack.mitre.org/groups/G0027
- documents.trendmicro.com/assets/white_papers/wp-uncovering-DRBco…
- learn.microsoft.com/en-us/unified-secops-platform/microsoft…
- research.nccgroup.com/2018/05/18/emissary-panda-a-potential-n…
- securelist.com/luckymouse-hits-national-data-center/86…
- thehackernews.com/2018/06/chinese-watering-hole-attack.ht…
- unit42.paloaltonetworks.com/emissary-panda-attacks-middle-east-gove…
- secureworks.com/research/bronze-union
- secureworks.com/research/threat-group-3390-targets-orga…
- trendmicro.com/en_us/research/21/d/iron-tiger-apt-upda…
- securelist.ru/luckymouse-hits-national-data-center/90…
- trendmicro.com/en_us/research/22/h/irontiger-compromis…
- virustotal.com/gui/file/6e3c3045bb9d0db4817ad0441ee3c9…
- otx.alienvault.com/pulse/5e734d45158714422bc4e774
- docs.google.com/document/d/1oYX3uN6KxIX_StzTH0s0yFNNoHD…
- x.com/skocherhan/status/1942043295292481785
- secureworks.com/research/a-peek-into-bronze-unions-tool…
- virustotal.com/gui/file/96e38c55174bf287fe0c21a4d8fa63…
- blog.eclecticiq.com/chinese-state-sponsored-cyber-espionage…
- medium.com/@Sebdraven/goblin-panda-continues-to-ta…
- otx.alienvault.com/pulse/5fd1090b830e4fba81b06cef
- otx.alienvault.com/pulse/6448506f7a10b2c157ec8fc4
- twitter.com/pancak3lullz/status/1286021877375303682
- twitter.com/pancak3lullz/status/1286027620740726785
- labs.bitdefender.com/wp-content/uploads/downloads/operation-…
- twitter.com/_marklech_/status/1268138088167018498
- trendmicro.com/en_us/research/22/l/probing-weaponized-…
- otx.alienvault.com/pulse/63ff5a60ca3dccd68551ba17
- medium.com/@Sebdraven/gobelin-panda-against-the-be…
- medium.com/@Sebdraven/goblin-panda-changes-the-dro…
- virustotal.com/gui/file/36fad80a5f328f487b20a3f5fc5f19…
- virustotal.com/gui/file/3443bb895444c1c7fa0beab54f93a7…
- virustotal.com/gui/file/db4497090a94d0189aa3c3f4fcee30…
- securelist.com/luckymouse-ndisproxy-driver/87914
- securelist.com/cycldek-bridging-the-air-gap/97157
- otx.alienvault.com/pulse/607094697706cc521d0f0788
- twitter.com/MeltX0R/status/1179800013150527488
- medium.com/@Sebdraven/rtf-royal-road-drops-a-new-b…
- secureworks.com/cyber-threat-intelligence/threats/threa…
39 more, and the report behind every indicator, in G0027.json.