Cyber Resilience

Threat actor · all actors

Threat Group-3390G0027 state

🇨🇳 CN

aka Threat Group-3390, Earth Smilodon, TG-3390, Emissary Panda, BRONZE UNION, APT27, Iron Tiger, LuckyMouse, Linen Typhoon, GreedyTaotie, TEMP.Hippo, Red Phoenix, Budworm, Group 35, ZipToken, Lucky Mouse, G0027, Iron Taurus, Circle Typhoon, SHORE CASTLE, TiltedTemple, DEV-0322

Last updated: 2026-08-22

5attributed CVEs
83ATT&CK techniques
18.2IDF score (tooling uniqueness)
2exclusive CVEs
2010–2026years active

About this actor

[Threat Group-3390](https://attack.mitre.org/groups/G0027) is a Chinese threat group that has extensively used strategic Web compromises to target victims.(Citation: Dell TG-3390) The group has been active since at least 2010 and has targeted organizations in the aerospace, government, defense, technology, energy, manufacturing and gambling/betting sectors.(Citation: SecureWorks BRONZE UNION June 2017)(Citation: Securelist LuckyMouse June 2018)(Citation: Trend Micro DRBControl February 2020)

Source: MITRE ATT&CK

Names & naming systems

Each vendor coins its own name for the same actor. Where a name follows a known scheme we attribute it; the rest are listed honestly as unclassified.

MITRE ATT&CKG-number catalogue id

G0027

Microsoftweather-system names

Linen TyphoonCircle Typhoon

CrowdStrikenation-animal names

Emissary PandaIron Tiger

Mandiant / genericAPT numbering

APT27

MandiantTEMP temporary cluster

TEMP.Hippo

Secureworkscolour-metal names

BRONZE UNION

Palo Alto Unit 42constellation names

Iron Taurus

Unclassifiedno scheme matched

Threat Group-3390Earth SmilodonTG-3390LuckyMouseGreedyTaotieRed PhoenixBudwormGroup 35ZipTokenLucky MouseSHORE CASTLETiltedTempleDEV-0322

How we know this

Data origin
MITRE ATT&CK Imported from the MITRE ATT&CK STIX bundle as an intrusion-set object.
Techniques
MITRE ATT&CK STIX mappings — 83 ATT&CK techniques on file.
Named victims
None on file.

See how actor data is built for the full pipeline.

Activity timeline

Profile

CVERiskCVSSEPSSPublishedProducts
CVE-2010-0738 KEV7.55.30.97462010-04-28see CVE
CVE-2017-15303 6.27.80.01552017-10-16see CVE
CVE-2026-31635 6.07.50.00822026-04-24see CVE
CVE-2026-21236 5.87.80.00422026-02-10see CVE
CVE-2026-45585 5.56.80.01352026-05-20see CVE

Mitigating controls (NIST 800-53)

ControlTechniques coveredCoverage
SI-451 / 8361%
CM-645 / 8354%
CM-241 / 8349%
SI-338 / 8346%
AC-637 / 8345%
AC-334 / 8341%
CM-733 / 8340%
AC-232 / 8339%
CA-730 / 8336%
SI-726 / 8331%
AC-525 / 8330%
IA-225 / 8330%
SI-225 / 8330%
CM-524 / 8329%
RA-524 / 8329%

Co-occurring actors

Similar actors

Similar TTPs

Overlapping CVEs

Active in same years

Same nation-state