Threat Group-3390 Targets Organizations for Cyberespionage | Dell SecureWorks
ID: c8b443be-2858-47bb-a5bc-271e538cc755
STIX ID: report--c8b443be-2858-47bb-a5bc-271e538cc755
Threat Score
88/100
Uploaded: 2026-08-07
Published Date: 2015-10-31
Last Modified Date: 2015-10-31
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Dell SecureWorks CTU analyzes TG-3390, a China-linked espionage group that uses strategic web compromises and targeted spearphishing to deliver backdoors (HttpBrowser/TokenControl, PlugX), Exchange-targeted web shells (OwaAuth), and credential theft to exfiltrate sensitive defense, industrial, and political information; the report documents TTPs, sample hashes, domains/IPs, timelines of intrusion and exfiltration, and detection/mitigation recommendations.
