Threat Group-3390
Threat Group-3390 is a China-based threat actor tracked under numerous aliases including APT27, APT6, Bowser, Bronze Union, Circle Typhoon, DEV-0322, Earth Smilodon, Emissary Panda, Emissary_Panda, Hippo, Iodine, Iron Taurus, Iron Tiger, Linen Typhoon, LuckyMouse, Lucky Mouse, Red Phoenix, TG-3390, UNC215, and Wekby2. The content describes the group as a China-based nation-state actor and notes that APT27 exploited CVE-2025-53770 targeting internet-connected on-premises Microsoft SharePoint servers to deploy web shells and obtain initial access. Individuals linked to APT27, including Yin Kecheng and Zhou Shuai, are described as having conducted hacking campaigns and sold stolen data to multiple customers, including some Chinese government entities. The group is also referenced as sharing tooling used in Operation SoftCell with other Chinese-affiliated threat groups including APT10 and APT40. Reported behaviors in the content include exploitation for privilege escalation (T1068), PowerShell execution (T1059.001), creation of new Windows services for persistence (T1543.003), luring victims into opening malicious files, hosting malicious payloads on Dropbox, and malware that creates a new service, sometimes named after configuration information, to gain persistence.
Know when an actor pivots toward your sector
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Targeting
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Where they're from
Attributed origin per open-source reporting.
- CN
Tradecraft
54 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
Associated malware families
49 malware families attributed to this actor across reporting.
44 additional families tracked in Mallory.
Associated vulnerabilities
35 CVEs this actor has used in observed campaigns. 35 of them exploited in the wild.
CVE-2025–53770 is a remote code execution vulnerability in Microsoft SharePoint with a CVSS score of 9.8. At the time of discovery, sustained exploitation attempts were observed against on premise SharePoint installations worldwide. This vulnerability is known to have been exploited by China based nation state threat actor groups APT27 and APT31, and by another China based ransomware gang Storm 2603, targeting internet connected SharePoint servers to deploy web shells and obtain initial access.
ToolShell is comprised of CVE-2025-53770, a remote code execution vulnerability, and CVE‑2025‑53771, a server spoofing vulnerability.
For instance, the Clop ransomware gang exploited a Serv-U remote code execution vulnerability (CVE-2021-35211) to breach corporate networks in a 2021 campaign. DEV-0322 Chinese hackers also deployed CVE-2021-35211 exploits in zero-day attacks starting in July 2021.
According to Microsoft, cyber threat actors have chained CVE-2025-49706 (a network spoofing vulnerability) and CVE-2025-49704 (a remote code execution (RCE) vulnerability) in an exploit chain known as “ToolShell” to gain unauthorized access to on-premise SharePoint servers.
According to Microsoft, cyber threat actors have chained CVE-2025-49706 (a network spoofing vulnerability) and CVE-2025-49704 (a remote code execution (RCE) vulnerability) in an exploit chain known as “ToolShell” to gain unauthorized access to on-premise SharePoint servers.
30 more CVEs tied to this actor tracked in Mallory.
Observables
144 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
Recent activity
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Conducted hacking campaigns and sold stolen data to multiple customers, including Chinese government entities, illustrating the data-brokering layer of Chinese cyber operations.
Referenced as one of the Chinese cyber threat groups used by researchers to label MSS-linked activity targeting Europe.
Listed as an associated threat actor in the detection annotation for exploitation of the public-facing PTC Windchill vulnerability CVE-2026-4681.
Chinese threat actor observed deploying CVE-2021-35211 exploits in zero-day attacks against SolarWinds Serv-U starting in July 2021.
The version that knows your environment.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.