Threat Group-3390 Targets Organizations for Cyberespionage — www.secureworks.com
ID: 3b28bfab-7ec8-4222-8250-4d9a35e8956f
STIX ID: report--3b28bfab-7ec8-4222-8250-4d9a35e8956f
Threat Score
90/100
Uploaded: 2026-08-07
Published Date: 2015-12-20
Last Modified Date: 2015-12-20
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Dell SecureWorks CTU analyzes TG-3390, an assessed China-linked cyberespionage group that uses long-running strategic web compromises (watering holes), targeted spearphishing, and selective IP whitelisting to deliver backdoors (HttpBrowser/TokenControl, PlugX) and Exchange-targeted web shells (OwaAuth, ChinaChopper). The report details TG-3390's tradecraft — exploitation (Java/CVE-2011-3544, JBoss/CVE-2010-0738), DLL sideloading persistence, credential theft, lateral movement, and large-scale selective exfiltration (hundreds of GB) — and provides mitigations plus extensive IOCs (domains, IPs, hashes, emails).
