German Intelligence Warns APT27 Targeting Businesses with HYPERBRO Malware via Exchange and Zoho Exploits

Germany's Federal Office for the Protection of the Constitution (BfV) has issued a cyber brief warning of an ongoing espionage campaign by Chinese threat group APT27 targeting German commercial enterprises with the HYPERBRO malware.

Exchange and Zoho as Entry Points

Since March 2021, attackers have been exploiting vulnerabilities in Microsoft Exchange and Zoho AdSelf Service Plus software to gain initial access to victim networks. The BfV warned that beyond stealing trade secrets and intellectual property, the actors may be attempting to infiltrate the networks of corporate customers and service providers — raising the specter of supply chain attacks rippling outward from initial compromises.

A Decade of Operations

APT27 — also known as Emissary Panda, LuckyMouse, and Iron Tiger — has been active since at least 2010. The BfV reported observing a notable increase in attacks against German targets, describing the campaign as a "continuing wave" against the German economy. The agency published detection rules and indicators of compromise (IOCs) to help organizations identify infections with both current and potentially future variants of HYPERBRO.

Implications for German Industry

The advisory is notable for its directness in attributing the campaign to a Chinese state-linked group — reflecting growing European willingness to publicly name nation-state cyber actors. German businesses in manufacturing, technology, and engineering sectors were urged to prioritize patching Exchange and Zoho instances and to scan for HYPERBRO indicators across their environments. The BfV emphasized that supply chain compromise potential makes this threat relevant not only to direct targets but to their entire partner ecosystems.

Read the full analysis on IntelFusions