Threat group.View on attack.mitre.org
Threat Group-3390 is a Chinese threat group that has extensively used strategic Web compromises to target victims. The group has been active since at least 2010 and has targeted organizations in the aerospace, government, defense, technology, energy, manufacturing and gambling/betting sectors.
| Technique | Procedure example |
|---|---|
| T1003.001 LSASS Memory |
Threat Group-3390 actors have used a modified version of Mimikatz called Wrapikatz to dump credentials. They have also dumped credentials from domain controllers. |
| T1003.002 Security Account Manager |
Threat Group-3390 actors have used gsecdump to dump credentials. They have also dumped credentials from domain controllers. |
| T1003.004 LSA Secrets |
Threat Group-3390 actors have used gsecdump to dump credentials. They have also dumped credentials from domain controllers. |
| T1005 Data from Local System |
Threat Group-3390 ran a command to compile an archive of file types of interest from the victim user's directories. |
| T1012 Query Registry |
A Threat Group-3390 tool can read and decrypt stored Registry values. |
| T1016 System Network Configuration Discovery |
Threat Group-3390 actors use NBTscan to discover vulnerable systems. |
| T1018 Remote System Discovery |
Threat Group-3390 has used the |
| T1021.006 Windows Remote Management |
Threat Group-3390 has used WinRM to enable remote execution. |
| T1027.002 Software Packing |
Threat Group-3390 has packed malware and tools, including using VMProtect. |
| T1027.013 Encrypted/Encoded File |
A Threat Group-3390 tool can encrypt payloads using XOR. Threat Group-3390 malware is also obfuscated using Metasploit’s shikata_ga_nai encoder. |
| T1027.015 Compression |
Threat Group-3390 malware is compressed with LZNT1 compression. |
| T1030 Data Transfer Size Limits |
Threat Group-3390 actors have split RAR files for exfiltration into parts. |
| T1033 System Owner/User Discovery |
Threat Group-3390 has used `whoami` to collect system user information. |
| T1046 Network Service Discovery |
Threat Group-3390 actors use the Hunter tool to conduct network service discovery for vulnerable systems. |
| T1047 Windows Management Instrumentation |
A Threat Group-3390 tool can use WMI to execute a binary. |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.