>samit_hota
Back to adversary profiles

Threat Actor Dossier

APT27 / Threat Group-3390: Profiling the Emissary Panda Operations

G0027

Also tracked as Earth Smilodon · TG-3390 · Emissary Panda · BRONZE UNION · APT27 · Iron Tiger · LuckyMouse · Linen Typhoon · 7 sectors targeted

Threat level
CRITICAL
Status
ACTIVE
Origin
China
Motivation
Espionage · Intellectual Property Theft
Samit Hota·
Target Sectors
Aerospace, Government, Defense, Technology, Energy, Manufacturing, Gambling
Associated Malware
HyperBro, SysUpdate, PlugX, Gh0st RAT, ZXShell, QuasarRAT
#threat-actor#g0027

For over a decade, security teams have tracked the sophisticated activity of Threat Group-3390, widely recognized by industry monitors as APT27, Emissary Panda, or BRONZE UNION. This actor is not a group that hides in the shadows; they are persistent, methodical, and arguably one of the most operationally stable units operating out of China. While many state-sponsored actors shift focus or disappear, this group has demonstrated a remarkable ability to evolve its tooling while maintaining a consistent mandate of long-term intelligence collection.

Operational Strategy and Targeting

What sets this group apart is its willingness to engage in high-value, high-stakes supply chain compromises. Rather than just targeting a single firm, they have historically compromised service providers to gain a beachhead into the broader infrastructure of their targets. Their reach is global, but they demonstrate a clear preference for the “crown jewels” of international industry: defense contractors, critical energy infrastructure, and, somewhat distinctively, the gambling and betting sector. The latter is often viewed as a mechanism for financial intelligence or money laundering oversight, but for APT27, it appears to be a consistent intelligence priority.

TTPs: From Waterholes to Exploits

The group is famous for its mastery of “strategic web compromises”—essentially, finding a niche site frequented by their targets, compromising it, and using it as a delivery vehicle for their exploits. Once inside a perimeter, they are master-class at lateral movement. They don’t just deploy malware; they live off the land, heavily leveraging Windows Management Instrumentation (WMI) and legitimate administrative tools to conduct reconnaissance while remaining below the radar of traditional signature-based detection.

They are known for being early adopters of new CVEs. Whenever a major vulnerability is disclosed in a common gateway product—VPNs, web servers, or cloud collaboration tools—you can usually expect to see this group actively scanning and weaponizing that vulnerability within days, if not hours.

The Toolkit

Their arsenal is extensive, though they rely heavily on a rotating suite of modular backdoors. The most infamous, HyperBro, is a classic hallmark of their operations—a highly customized remote access trojan designed for stealthy data exfiltration and command execution. Beyond that, they have a deep bench of tools including SysUpdate, which they often use for persistent access, and the perennial favorite, PlugX, which they deploy in various modified versions to ensure it bypasses evolving EDR heuristics.

Current Stance

APT27 is far from dormant. They have increasingly integrated ransomware-style encryption not necessarily for financial gain, but as a disruptive “smoke screen” during their later-stage exfiltration efforts. By encrypting systems during their exit, they complicate forensic investigations and buy themselves the time needed to scrub their footprints. Any organization in the aerospace or government technology space should assume this group is a permanent part of their threat model; they are not the type to hit-and-run, they are the type to stay until they have exactly what they came for.

Worried this actor targets your sector?

Let's map your exposure before they find it themselves.

Book an advisory call