APT27 — APT Profile
A China-based actor that targets foreign embassies to collect data on government, defence, and technology sectors.Also tracked as
Threat Group-3390, Earth Smilodon, TG-3390, Emissary Panda, BRONZE UNION, Iron Tiger, LuckyMouse, Linen Typhoon
Tools & malware
- asp.twoface Web Shell
- elf.hyperssl Backdoor
- win.chinachopper Web Shell
- win.ghost_rat Remote Access Trojan
- win.httpbrowser Backdoor
- win.hyperbro Backdoor
- win.hyperssl Backdoor
- win.plugx Backdoor
- win.polpo Backdoor
- win.unidentified_080 Backdoor
- win.zxshell Remote Access Trojan
Vendor research
- Emissary Panda – A potential new malicious tool Pantazopoulos, N., Henry T
- BRONZE UNION Cyberespionage Persists Despite Disclosures Counter Threat Unit Research Team
- Threat Group-3390 Targets Organizations for Cyberespionage Dell SecureWorks Counter Threat Unit Threat Intelligence
- Emissary Panda Attacks Middle East Government Sharepoint Servers Falcone, R. and Lancaster, T
- Newly discovered Chinese hacking group hacked 100+ websites to use as “watering holes” Gallagher, S.
- Chinese Hackers Carried Out Country-Level Watering Hole Attack Khandelwal, S
- LuckyMouse hits national data center to organize country-level waterholing campaign Legezo, D
- Iron Tiger APT Updates Toolkit With Evolved SysUpdate Malware Lunghi, D. and Lu, K
- Uncovering DRBControl Lunghi, D. et al
- How Microsoft names threat actors Microsoft