ATT&CKGroupsThreat Group-3390

Threat Group-3390

G0027

Threat group.View on attack.mitre.org

About this group

Threat Group-3390 is a Chinese threat group that has extensively used strategic Web compromises to target victims. The group has been active since at least 2010 and has targeted organizations in the aerospace, government, defense, technology, energy, manufacturing and gambling/betting sectors.

Techniques used57

Procedure examples57

TechniqueProcedure example
T1003.001
LSASS Memory

Threat Group-3390 actors have used a modified version of Mimikatz called Wrapikatz to dump credentials. They have also dumped credentials from domain controllers.

T1003.002
Security Account Manager

Threat Group-3390 actors have used gsecdump to dump credentials. They have also dumped credentials from domain controllers.

T1003.004
LSA Secrets

Threat Group-3390 actors have used gsecdump to dump credentials. They have also dumped credentials from domain controllers.

T1005
Data from Local System

Threat Group-3390 ran a command to compile an archive of file types of interest from the victim user's directories.

T1012
Query Registry

A Threat Group-3390 tool can read and decrypt stored Registry values.

T1016
System Network Configuration Discovery

Threat Group-3390 actors use NBTscan to discover vulnerable systems.

T1018
Remote System Discovery

Threat Group-3390 has used the net view command.

T1021.006
Windows Remote Management

Threat Group-3390 has used WinRM to enable remote execution.

T1027.002
Software Packing

Threat Group-3390 has packed malware and tools, including using VMProtect.

T1027.013
Encrypted/Encoded File

A Threat Group-3390 tool can encrypt payloads using XOR. Threat Group-3390 malware is also obfuscated using Metasploit’s shikata_ga_nai encoder.

T1027.015
Compression

Threat Group-3390 malware is compressed with LZNT1 compression.

T1030
Data Transfer Size Limits

Threat Group-3390 actors have split RAR files for exfiltration into parts.

T1033
System Owner/User Discovery

Threat Group-3390 has used `whoami` to collect system user information.

T1046
Network Service Discovery

Threat Group-3390 actors use the Hunter tool to conduct network service discovery for vulnerable systems.

T1047
Windows Management Instrumentation

A Threat Group-3390 tool can use WMI to execute a binary.

View all 57 procedure examples

Software24

Campaigns0

None recorded.

References4

  1. Dell TG-3390 Open source
    Dell SecureWorks Counter Threat Unit Threat Intelligence. (2015, August 5). Threat Group-3390 Targets Organizations for Cyberespionage. Retrieved August 18, 2018.
  2. SecureWorks BRONZE UNION June 2017 Open source
    Counter Threat Unit Research Team. (2017, June 27). BRONZE UNION Cyberespionage Persists Despite Disclosures. Retrieved July 13, 2017.
  3. Securelist LuckyMouse June 2018 Open source
    Legezo, D. (2018, June 13). LuckyMouse hits national data center to organize country-level waterholing campaign. Retrieved August 18, 2018.
  4. Trend Micro DRBControl February 2020 Open source
    Lunghi, D. et al. (2020, February). Uncovering DRBControl. Retrieved November 12, 2021.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.