logo

Threat Group-3390 Targets Organizations for Cyberespionage | Dell SecureWorks

ID: c8b443be-2858-47bb-a5bc-271e538cc755

STIX ID: report--c8b443be-2858-47bb-a5bc-271e538cc755

Threat Score

88/100

Uploaded: 2026-08-07

Published Date: 2015-10-31

Last Modified Date: 2015-10-31

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Dell SecureWorks CTU analyzes TG-3390, a China-linked espionage group that uses strategic web compromises and targeted spearphishing to deliver backdoors (HttpBrowser/TokenControl, PlugX), Exchange-targeted web shells (OwaAuth), and credential theft to exfiltrate sensitive defense, industrial, and political information; the report documents TTPs, sample hashes, domains/IPs, timelines of intrusion and exfiltration, and detection/mitigation recommendations.