APT27

πŸ”΄ High
Also known as: GreedyTaotie, TG-3390, EMISSARY PANDA, TEMP.Hippo, Red Phoenix, Budworm, Group 35, ZipToken, Iron Tiger, BRONZE UNION, Lucky Mouse, G0027, Iron Taurus, Earth Smilodon, Circle Typhoon, Linen Typhoon, APT27, DEV-0322, APT6, IODINE, Hippo, BOWSER, Wekby2, UNC215, 1.php Group

A China-based actor that targets foreign embassies to collect data on government, defence, and technology sectors.

🌍 Country China
⚑ Risk Level High
🎯 Incident Type Espionage
Technology Government, Administration Defense Government Private sector

Introduction

A China-based actor that targets foreign embassies to collect data on government, defence, and technology sectors.

Activities and Tactics

Targeted Sectors: Technology, Government, Administration, Defense, Government, Private sector

Country of Origin: πŸ‡¨πŸ‡³ China

Risk Level: High

Incident Type: Espionage

Suspected Victims: United States, United Kingdom, France, Japan, Taiwan, India, Canada, China, Thailand, Israel…

Notable Campaigns

Information pending cataloguing.

Tactics, Techniques, and Procedures (TTPs)

Information pending cataloguing.

Notable Indicators of Compromise (IOCs)

No curated IOCs are currently published for this actor. This section will be updated when stable, attributable indicators are available.

Malware and Tools

  • China Chopper

Attribution and Evidence

Country of Origin: China Additional attribution information pending cataloguing.

References

References pending cataloguing.