- Target Sectors
- Aerospace, Government, Defense, Technology, Energy, Manufacturing, Gambling
- Associated Malware
- HyperBro, SysUpdate, PlugX, Gh0st RAT, ZXShell, QuasarRAT
For over a decade, security teams have tracked the sophisticated activity of Threat Group-3390, widely recognized by industry monitors as APT27, Emissary Panda, or BRONZE UNION. This actor is not a group that hides in the shadows; they are persistent, methodical, and arguably one of the most operationally stable units operating out of China. While many state-sponsored actors shift focus or disappear, this group has demonstrated a remarkable ability to evolve its tooling while maintaining a consistent mandate of long-term intelligence collection.
Operational Strategy and Targeting
What sets this group apart is its willingness to engage in high-value, high-stakes supply chain compromises. Rather than just targeting a single firm, they have historically compromised service providers to gain a beachhead into the broader infrastructure of their targets. Their reach is global, but they demonstrate a clear preference for the “crown jewels” of international industry: defense contractors, critical energy infrastructure, and, somewhat distinctively, the gambling and betting sector. The latter is often viewed as a mechanism for financial intelligence or money laundering oversight, but for APT27, it appears to be a consistent intelligence priority.
TTPs: From Waterholes to Exploits
The group is famous for its mastery of “strategic web compromises”—essentially, finding a niche site frequented by their targets, compromising it, and using it as a delivery vehicle for their exploits. Once inside a perimeter, they are master-class at lateral movement. They don’t just deploy malware; they live off the land, heavily leveraging Windows Management Instrumentation (WMI) and legitimate administrative tools to conduct reconnaissance while remaining below the radar of traditional signature-based detection.
They are known for being early adopters of new CVEs. Whenever a major vulnerability is disclosed in a common gateway product—VPNs, web servers, or cloud collaboration tools—you can usually expect to see this group actively scanning and weaponizing that vulnerability within days, if not hours.
The Toolkit
Their arsenal is extensive, though they rely heavily on a rotating suite of modular backdoors. The most infamous, HyperBro, is a classic hallmark of their operations—a highly customized remote access trojan designed for stealthy data exfiltration and command execution. Beyond that, they have a deep bench of tools including SysUpdate, which they often use for persistent access, and the perennial favorite, PlugX, which they deploy in various modified versions to ensure it bypasses evolving EDR heuristics.
Current Stance
APT27 is far from dormant. They have increasingly integrated ransomware-style encryption not necessarily for financial gain, but as a disruptive “smoke screen” during their later-stage exfiltration efforts. By encrypting systems during their exit, they complicate forensic investigations and buy themselves the time needed to scrub their footprints. Any organization in the aerospace or government technology space should assume this group is a permanent part of their threat model; they are not the type to hit-and-run, they are the type to stay until they have exactly what they came for.
Related content
PittyTiger: Persistent Espionage from the Far East
Adversary ProfileAxiom (G0001): Profile of a Sophisticated Chinese Cyber Espionage Group
Adversary ProfileAPT17 (Deputy Dog): A Persistent Chinese Cyber Espionage Threat
Adversary ProfilemenuPass (G0045): China's Enduring Cyber Espionage Arm
Worried this actor targets your sector?
Let's map your exposure before they find it themselves.
Book an advisory call