APT27 is a China-linked cyber espionage threat actor widely tracked under numerous aliases including Emissary Panda, LuckyMouse, Iron Tiger, Bronze Union, Circle Typhoon, Linen Typhoon, TG-3390, and Threat Group-3390. It is generally assessed to operate in support of Chinese state interests, while some reporting also indicates overlap between espionage activity and financially motivated data theft or resale by individuals associated with the cluster. APT27 has historically targeted governments, defense-related entities, critical infrastructure, technology organizations, and other strategic sectors. The group is known for compromising internet-facing enterprise systems and then using that access for espionage, credential theft, lateral movement, persistence, and data exfiltration. Reporting also links the actor to exploitation of Microsoft SharePoint vulnerabilities, including activity against exposed on-premises SharePoint servers and deployment of web shells to obtain initial access. Observed tradecraft includes exploitation of public-facing applications, use of PowerShell for execution, privilege escalation, Windows service creation or abuse for persistence, and extensive use of Windows Registry modifications for persistence and configuration handling. The group has been associated with Registry Run key persistence, creation of service-related Registry entries, and querying or decrypting stored Registry values for discovery and operational purposes. ATT&CK techniques associated with the actor in available reporting include Exploitation for Privilege Escalation, PowerShell, Setuid and Setgid abuse, and Windows Service persistence. APT27 is part of the broader ecosystem of Chinese state-linked intrusion activity in which contractors, private firms, and affiliated operators may play distinct roles across intrusion, tooling, and monetization. Public reporting has identified individuals linked to APT27 who conducted hacking campaigns and sold stolen data to multiple customers, including Chinese government entities. This reinforces the assessment that the cluster spans both state-aligned espionage and commercially motivated activity. Known aliases and related tracking names include APT6, Bowser, Bronze Union, Circle Typhoon, DEV-0322, Earth Smilodon, Emissary Panda, Hippo, Iodine, Iron Taurus, Iron Tiger, Linen Typhoon, LuckyMouse, Red Phoenix, UNC215, and Wekby2.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Attributed origin per open-source reporting.
53 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
49 malware families attributed to this actor across reporting.
44 additional families tracked in Mallory.
35 CVEs this actor has used in observed campaigns. 35 of them exploited in the wild.
On July 19, 2025, security researchers and enterprise defenders began tracking a large-scale exploitation campaign targeting on-premises Microsoft SharePoint Servers (CVE-2025-53770). On July 19th, Microsoft confirmed that a zero day vulnerability impacting on-premises Microsoft SharePoint Servers, dubbed “ToolShell”. CVE-2025-53770 has been added to CISA’s Known Exploited Vulnerabilities (KEV) catalog on July 20, 2025.
CVE-2025-53771 : Type: Input Validation / Path Traversal Used to overwrite or plant files in sensitive directories, aiding persistence.
Researchers also identified Linen Typhoon, Violet Typhoon, and Storm-2603 had in fact started using the two flaws (CVE-2025-49706 and CVE-2025-49704) as zero-days, based on its investigation into ongoing attacks on SharePoint Servers. CVE-2025-49704 : Type: Unauthenticated File Upload Allows arbitrary .aspx files (webshells) to be written to accessible paths.
Researchers also identified Linen Typhoon, Violet Typhoon, and Storm-2603 had in fact started using the two flaws (CVE-2025-49706 and CVE-2025-49704) as zero-days, based on its investigation into ongoing attacks on SharePoint Servers. CVE-2025-49706 : Type: XAML Deserialization Enables post-auth remote code execution (RCE).
For instance, the Clop ransomware gang exploited a Serv-U remote code execution vulnerability (CVE-2021-35211) to breach corporate networks in a 2021 campaign. DEV-0322 Chinese hackers also deployed CVE-2021-35211 exploits in zero-day attacks starting in July 2021.
30 more CVEs tied to this actor tracked in Mallory.
238 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Listed as an annotation/tag associated with privilege escalation techniques in the detection content; no campaign or activity by the group is described in this reference.
Conducted hacking campaigns and sold stolen data to multiple customers, including Chinese government entities, illustrating the data-brokering layer of Chinese cyber operations.
Referenced as one of the Chinese cyber threat groups used by researchers to label MSS-linked activity targeting Europe.
Listed as an associated threat actor in the detection annotation for exploitation of the public-facing PTC Windchill vulnerability CVE-2026-4681.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.