Chinese cyber espionage group APT27 — also tracked as Emissary Panda, Iron Tiger, and Budworm — remains one of the most persistent nation-state threats in 2025, with fresh U.S. indictments and ongoing global C2 activity confirmed by multiple sources, according to a comprehensive threat actor profile published by Dexpose.
DOJ Unseals Charges Against APT27 Operators
On March 5, 2025, the U.S. Department of Justice unsealed charges against 12 Chinese nationals involved in global intrusion campaigns. Among them, Yin Kecheng and Zhou Shuai (aka "Coldface") were identified as APT27 members who conducted unauthorized intrusions from August 2013 through December 2024 — including a breach of the U.S. Department of the Treasury. The DOJ reported that Zhou brokered stolen data through i-Soon, whose primary customers included China's Ministry of State Security and Ministry of Public Security.
The U.S. Treasury sanctioned both individuals and Zhou's company, Shanghai Heiying Information Technology Co., Ltd., while the State Department offered $2 million rewards for information leading to their arrests. Both remain at large in China.
SysUpdate C2 Active in 45 Countries
Palo Alto's Unit 42 confirmed in June 2025 that APT27's custom SysUpdate backdoor infrastructure remains actively receiving connections from devices in 45 countries, with the highest volumes from Taiwan, Afghanistan, India, and China. The group's toolset spans a formidable arsenal including HyperBro, PlugX, ShadowPad, China Chopper, and Mimikatz, deployed through signature DLL sideloading techniques abusing signed binaries from Symantec, McAfee, Google, and even Wazuh.
15 Years of Evolving Tradecraft
The Dexpose profile catalogs APT27's evolution from early spear-phishing campaigns through supply-chain compromises of chat applications (Able Desktop in Mongolia, MiMi targeting Taiwan and the Philippines), exploitation of ProxyLogon, Log4j, and Zoho ManageEngine vulnerabilities, and suspected ransomware operations using Polar and BitLocker. The group has also expanded to cross-platform targeting with Linux and macOS variants of its backdoors.
APT27's dual focus on state-aligned espionage and financially motivated intrusions — combined with its demonstrated willingness to operate across government, defense, healthcare, telecoms, and gaming sectors — makes it one of the most versatile Chinese threat actors currently tracked.