logo

Threat Group-3390 Targets Organizations for Cyberespionage — www.secureworks.com

ID: 3b28bfab-7ec8-4222-8250-4d9a35e8956f

STIX ID: report--3b28bfab-7ec8-4222-8250-4d9a35e8956f

Threat Score

90/100

Uploaded: 2026-08-07

Published Date: 2015-12-20

Last Modified Date: 2015-12-20

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Dell SecureWorks CTU analyzes TG-3390, an assessed China-linked cyberespionage group that uses long-running strategic web compromises (watering holes), targeted spearphishing, and selective IP whitelisting to deliver backdoors (HttpBrowser/TokenControl, PlugX) and Exchange-targeted web shells (OwaAuth, ChinaChopper). The report details TG-3390's tradecraft — exploitation (Java/CVE-2011-3544, JBoss/CVE-2010-0738), DLL sideloading persistence, credential theft, lateral movement, and large-scale selective exfiltration (hundreds of GB) — and provides mitigations plus extensive IOCs (domains, IPs, hashes, emails).