APT27 is a China-linked cyber-espionage threat actor widely known as Emissary Panda, Iron Tiger, and LuckyMouse. The group has been active for more than a decade and is associated with long-running intelligence collection and intellectual property theft operations. Reporting consistently places it within the broader Chinese state-backed intrusion ecosystem. APT27 is known for targeting government organizations and other strategic entities, including operations against Middle Eastern government networks and broader activity affecting Central Asian and Middle Eastern government bodies. The actor has also been associated with compromises of internet-facing enterprise platforms, notably Microsoft SharePoint, to gain footholds in victim environments. The group has used exploitation of public-facing vulnerabilities for initial access, including CVE-2019-0604 in SharePoint, followed by deployment of web shells such as China Chopper to establish persistence and enable follow-on intrusion activity. Observed tradecraft includes use of backdoors and remote shell implants, with reporting noting cross-platform targeting that included Linux and macOS through an Rshell Mach-O implant. The actor’s operations are consistent with espionage-focused post-compromise behavior, including persistent access, stealthy footholds, and likely internal pivoting after server compromise. APT27 overlaps in public reporting with aliases and cluster names including Emissary Panda, Iron Tiger, and LuckyMouse. Some reporting also references APT6 in connection with the same activity, though aliasing across vendors is not always perfectly consistent. The actor is best characterized as a Chinese cyber-espionage group focused on long-term access to government and strategic targets.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Attributed origin per open-source reporting.
19 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
6 malware families attributed to this actor across reporting.
1 additional family tracked in Mallory.
2 CVEs this actor has used in observed campaigns. 2 of them exploited in the wild.
Although LuckyMouse has been spotted using a widely used Microsoft Office vulnerability (CVE-2017-11882) to weaponize Office documents in the past, researchers have no proofs of this technique being used in this particular attack against the data center.
CVE-2019-0604, a critical vulnerability opening unpatched Microsoft SharePoint servers to attack, is being exploited by attackers to install a web shell... A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an application package...
22 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Linen Typhoon is a Chinese state-backed threat actor known for conducting espionage attacks and intellectual property theft, recently observed exploiting the ToolShell (CVE-2025-53770) vulnerability in Microsoft SharePoint to compromise government, telecom, and academic organizations worldwide.
APT27 is a Chinese cyber-espionage group known for targeting organizations for intelligence gathering.
Lucky Mouse is a China-nexus threat actor known for targeting government and technology sectors, developing cross-platform malware, and leveraging spearphishing and supply chain attacks.
LuckyMouse is a Chinese-speaking APT group targeting government organizations in the Middle East, exploiting SharePoint vulnerabilities and using web shells for further compromise.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.