news.mlab.sh
Threat intelligence
Threat actor

Emissary Panda

Profile from actors.mlab.sh, coverage from our own index.

Suspected origin
China
First seen
2010-01-01 00:00:00
Motivation
Information theft and espionage
Targeted sectors
Aerospace, Aviation, Defense, Education, Embassies, Government, Manufacturing, Technology, Telecommunications, Think Tanks
TLP
WHITE

Threat Group-3390 is a Chinese threat group that has extensively used strategic Web compromises to target victims. The group has been active since at least 2010 and has targeted organizations in the aerospace, government, defense, technology, energy, and manufacturing sectors. Emissary Panda has some overlap with Turbine Panda, APT 26, Shell Crew, WebMasters, KungFu Kittens and possibly UNC215. This actor worked together with TA428 in Operation StealthyTrident.

Also known as

APT 27APT27ATK 15Bronze UnionBudwormCircle TyphoonEarth SmilodonEmissary PandaG0027Group 35Iron TaurusIron TigerLinen TyphoonLuckyMouseRed PhoenixTEMP.HippoTG-3390Threat Group-3390ZipToken

Vulnerabilities exploited

Tooling and malware

ASPXSpyChina ChopperClamblingCobalt Strikegh0st RATHTTPBrowserHyperBroPandoraPlugXRCSessionSysUpdateZxShellcertutilgsecdumpImpacketipconfigMimikatzNBTscanNetnetstatpwdumpSysteminfoTasklistWindows Credential Editor

MITRE ATT&CK techniques

T1005 Data from Local SystemT1119 Automated CollectionT1105 Ingress Tool TransferT1112 Modify RegistryT1012 Query RegistryT1016 System Network Configuration DiscoveryT1018 Remote System DiscoveryT1033 System Owner/User DiscoveryT1046 Network Service DiscoveryT1049 System Network Connections DiscoveryT1047 Windows Management InstrumentationT1203 Exploitation for Client ExecutionT1030 Data Transfer Size LimitsT1189 Drive-by CompromiseT1190 Exploit Public-Facing ApplicationT1199 Trusted RelationshipT1210 Exploitation of Remote ServicesT1133 External Remote ServicesT1068 Exploitation for Privilege EscalationT1078 Valid AccountsT1140 Deobfuscate/Decode Files or Information

Coverage 1