APT-Q-27
APT-Q-27, also known as GoldenEyeDog and Dragon Breath, is a Chinese-nexus threat group that has been active since at least 2022. Reporting in the provided content links the group to campaigns targeting gambling, cryptocurrency, and Web3 organizations, including customer support teams. In one active campaign, the group posed as customers in live support chats and sent fake screenshot shortlinks that delivered a .pif executable disguised as an image. The malware chain used a multi-stage design: retrieval of additional components from an AWS S3 bucket via a manifest, DLL sideloading using a legitimate YY platform binary (updat.exe), decryption and in-memory execution of payloads from files such as yyext.log or updat.log, and a final persistent backdoor. Observed persistence and defense-evasion behaviors included registry Run keys, Windows service creation including the misspelled service name "Windows Eventn.", registry modifications, UAC disabling through three registry keys, obfuscated executables, reflective or in-memory loading, and cleanup activity. The implant communicated over TCP port 15628 with 37 hardcoded command-and-control servers in one campaign. Runtime artifacts associated with the group in the content include the mutex Global\DHGGlobalMutex and registry keys HKCU\offlinekey\open and HKCU\offlinekey\clipboard; the latter are described as settings related to keylogging and clipboard hijacking. Additional reporting ties APT-Q-27 to the long-running sims-4-updater malware campaign, including a 2026 sample signed with a DigiCert EV code-signing certificate issued to MobSoft Co., Ltd, using live infrastructure such as lightindividual.com and dead-drop resolvers on rentry.co, rentry.org, and gist.githubusercontent.com. CyStack also reported a mid-January 2026 intrusion in a corporate customer support environment whose command-and-control infrastructure, modular backdoor design, multi-stage architecture, and use of an encrypted payload container resembled prior APT-Q-27 activity, though that attribution was not definitive.
Know when an actor pivots toward your sector
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Targeting
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Who they target
Sectors the actor has been observed targeting.
- Commercial & Professional Services
Where they're from
Attributed origin per open-source reporting.
- HK
- JP
- US
- IN
Tradecraft
36 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
Associated malware families
5 malware families attributed to this actor across reporting.
Observables
100 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
Recent activity
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Linked to the long-running sims-4-updater malware distribution campaign, using a custom PE64 backdoor, EV code-signing abuse, live C2 infrastructure, and dead-drop resolvers via rentry.co/rentry.org/GitHub gist. The group is also described as historically targeting gambling operators and Chinese-speaking gambling players in Southeast Asia, and was tied to a January 2026 corporate intrusion in Vietnam.
Conducting social-engineering-based intrusions against Web3 customer support teams by posing as customers in support chats and delivering a multi-stage backdoor via fake screenshot links. The group has been active since at least 2022 and has a history of targeting the gambling and cryptocurrency sectors.
A sophisticated multi-stage intrusion linked by infrastructure and tradecraft similarities to prior APT-Q-27 activity. The campaign used a phishing-delivered .pif dropper, digitally signed malware, DLL sideloading, persistence via registry and Windows services, in-memory payload execution, and a modular plugin-based backdoor architecture.
The version that knows your environment.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.