Home/Threat Actor/APT27
Threat Actor

APT27

emissary_panda · china · active since 2010

APT27 (Emissary Panda / LuckyMouse / TG-3390 / Bronze Union / Iron Tiger / G0027) is one of the longest-running publicly-tracked China-aligned cyber-espionage clusters, active since at least 2010 and widely assessed to operate with MSS tasking, responsible for sustained operations against US, European, Middle Eastern, Russian, Indian, and Asia-Pacific government, defense, aerospace, energy, technology, manufacturing, healthcare, higher-education, religious- organization, and dissident targets using a signature HyperBro + SysUpdate + ZxShell toolkit alongside PlugX, ShadowPad, and ecosystem-shared tooling, plus a notable post-2019 pivot toward financially-motivated Polar / HelloKitty-variant ransomware operations against online-gambling and gaming-industry targets that mirrors the dual-motivation pattern of APT41, Earth Lusca, and RedHotel.

china confidence: high 26 aliases MITRE ATT&CK G0027 ↗

Profile

APT27 (also tracked as Emissary Panda, LuckyMouse, TG-3390, Bronze Union, Iron Tiger, ZipToken, Earth Smilodon, Red Phoenix, and MITRE ATT&CK G0027) is a China-aligned cyber-espionage cluster active since at least 2010 and one of the longest-running publicly-tracked Chinese state-aligned actors. The cluster was independently named and characterized by multiple vendors in the mid-2010s, Dell Secureworks Counter Threat Unit's seminal August 2015 "Threat Group 3390" disclosure, Trend Micro's parallel September 2015 "Operation Iron Tiger" disclosure, FireEye/Mandiant's APT27 designation, CrowdStrike's Emissary Panda designation, and Kaspersky's LuckyMouse designation, all subsequently consolidated into the unified APT27 cluster characterization. The cluster is widely assessed to operate with MSS (Ministry of State Security) tasking, with some assessments placing operations geographically with MSS Hubei province / Wuhan- area adjacency (partially overlapping the geographic profile of APT31, separately covered, attributed by DOJ to MSS Hubei / Wuhan XRZ Science and Technology). The MSS-Hubei adjacency for APT27 is suggested rather than formally established.

no formal US, UK, or EU government attribution to a specific PRC ministry or unit has been published. The cluster's core toolkit centers on three signature implants that have evolved across more than a decade: HyperBro (a modular Windows backdoor providing command execution, file operations, screenshot capture, and lateral-movement capability), SysUpdate (a multi-stage Windows implant with extensive configuration-driven flexibility), and ZxShell (a feature-rich legacy Chinese RAT framework originally developed by Chinese cybercrime communities and adopted across multiple Chinese- aligned clusters). PlugX / Korplug and ShadowPad supplement the core toolkit, alongside the legacy HKNetMgr and ChinaChopper / ASProxy web shells and the more recently-disclosed Owowa malicious IIS module (Kaspersky December 2021) and Moriya kernel-mode rootkit (Kaspersky May 2021, Operation TunnelSnake). The cluster has also been a heavy user of HTRAN and Earthworm proxy tooling for traffic redirection within victim networks. Targeting focus has historically centered on US, UK, German, French, Spanish, Italian, Turkish, Russian, Israeli, Middle Eastern, Indian, Mongolian, Tibetan, Hong Kong, Taiwanese, Vietnamese, Philippine, Thai, Kazakh, Kyrgyz, and Tajik government, defense, defense-industrial-base, aerospace, energy (oil-and-gas, nuclear), technology, telecommunications, manufacturing, automotive, healthcare, pharmaceutical, higher- education, research, religious-organization (Tibetan especially), and dissident-community targets. The 2018 Kaspersky disclosure of LuckyMouse compromising a Central Asian national data center is among the most operationally consequential publicly-documented operations in the cluster's history, demonstrating the cluster's capability for compromise of entire-country digital-infrastructure hosts. A defining post-2019 development for APT27 is the cluster's documented pivot toward financially-motivated ransomware operations alongside its longstanding espionage portfolio. Profero and Trend Micro have published detailed attribution of Polar ransomware deployment to APT27 / Bronze Union actors against online-gambling and gaming-industry targets in 2020-2022. The dual-motivation pattern mirrors APT41, Earth Lusca, and RedHotel (all already covered in this corpus) and is consistent with assessed PRC-state tolerance of MSS-affiliated cluster moonlighting. The ransomware pivot raises ongoing analytic questions about whether the financial operations represent sanctioned moonlighting (with operators retaining ransom proceeds) or a separate funding stream for cluster operations. A handful of operational notes: First, APT27 is operationally distinct from APT19 (Deep Panda / Shell Crew), which has historically caused attribution confusion due to overlapping victimology in mid-2010s reporting and shared tooling ecosystems. The OPM (2015) and Anthem healthcare (2015) breaches were eventually attributed primarily to Deep Panda / APT19, with APT27 framed as ecosystem-adjacent rather than as the primary operator. Second, the cluster shares tooling (PlugX, ShadowPad) with the broader Chinese-state-aligned tooling ecosystem, complicating attribution at the malware-family level. Cluster-level operational signatures (HyperBro and SysUpdate specifically, plus infrastructure and victimology) remain the most reliable attribution signals. Third, MSS-alignment attribution, though dominant in vendor reporting, has not been confirmed by formal state attribution and should be presented as suspected.

Aliases

26
apt27apt-27apt 27emissary pandaemissary_pandaemissarypandaluckymouselucky mouselucky_mousetg-3390tg_3390threat group 3390threat_group_3390bronze unionbronze_unioniron tigeriron_tigerziptokenearth smilodonearth_smilodonred phoenixred_phoenixg0027atk 15atk15polar ransomware operator

MITRE ATT&CK aliases

1
Additional names MITRE lists for G0027.
Linen Typhoon

Notable Campaigns

8
2023-2025Continued Espionage and Ransomware Operations (2023-2025)
2021Operation TunnelSnake, Moriya Rootkit Disclosure (Kaspersky, May 2021)
2021Owowa IIS Module Disclosure (Kaspersky, December 2021)
2020-2022Polar Ransomware and Financially-Motivated Pivot (2020-2022)
2016-2020Tibetan and Religious-Organization Targeting (2016-2020)
2015Dell Secureworks CTU: Threat Group 3390 Targets Organizations for Cyberespionage (August 2015)
2015Trend Micro: Operation Iron Tiger (September 2015)
2014-2015OPM-Adjacent Targeting and Anthem Healthcare Adjacency (2014-2015)

Attribution & Reporting

Attributed by
Dell Secureworks Counter Threat UnitTrend MicroKaspersky GReATFireEye / MandiantCrowdStrikeMicrosoftNTT SecurityPWCESETSymantecCisco TalosSentinelOneVolexityProferoGroup-IBRecorded Future Insikt GroupCluster25CyfirmaSophosQiAnXin RedDrip360 Threat Intelligence Center
Key reporting
reportDell Secureworks Counter Threat Unit: Threat Group 3390 Targets Organizations for Cyberespionage (August 5, 2015), seminal cluster disclosure
reportTrend Micro: Operation Iron Tiger, Exploring Chinese Cyber-Espionage Against US Defense Contractors (September 2015)
reportSecureworks: Bronze Union Threat Profile
reportPWC: Red Phoenix / Emissary Panda Cyber-Espionage Operations (2017)
reportNTT Security: Global Threat Intelligence Report 2018, LuckyMouse Section
reportKaspersky GReAT: LuckyMouse Hits National Data Center (June 2018)
reportKaspersky GReAT: Operation TunnelSnake, Moriya Rootkit (May 2021)
reportKaspersky GReAT: Owowa Malicious IIS Module (December 2021)
reportCrowdStrike: Who Is Emissary Panda? (multiple years)
reportTrend Micro: Iron Tiger, Compromised Chat App Mimi Targets Windows, Mac, Linux Users (August 2022)
reportProfero / PwC: Polar Ransomware Attribution to APT27 (2021)
reportProfero / Security Joes: HelloKitty Ransomware Attribution to Chinese Actors (December 2020)
reportMandiant: APT27 Targets German Companies (multiple years)
reportCitizen Lab: Tibetan Targeting by APT27 / Emissary Panda (multiple years)
reportCluster25: APT27 Continued Operational Profile (2023-2024)
reportCyfirma: APT27 Emissary Panda Tracking (multiple years)
reportMalpedia Actor Profile: APT27
reportMITRE ATT&CK Group G0027, Emissary Panda / APT27

Operational

State sponsor

Suspected China-aligned advanced persistent threat group, widely assessed by vendor research (Dell Secureworks Counter Threat Unit's seminal August 2015 TG-3390 disclosure, Trend Micro's parallel Iron Tiger reporting, Kaspersky's LuckyMouse tracking, FireEye/ Mandiant's APT27 designation, and many subsequent vendors) to operate in alignment with Chinese state interests, likely with MSS (Ministry of State Security) tasking. Some assessments place APT27 operations geographically with MSS Hubei province / Wuhan- area infrastructure adjacency, partially overlapping the geographic profile of APT31 (separately covered as apt31_zirconium.yaml, attributed by DOJ to MSS Hubei / Wuhan XRZ Science and Technology), though APT27 is operationally distinct and the geographic MSS-Hubei adjacency for APT27 is suggested rather than formally established. The cluster has demonstrated a notable post-2019 pivot toward financially-motivated ransomware operations alongside its longstanding espionage portfolio, mirroring the dual-motivation pattern seen in APT41, Earth Lusca, and RedHotel, and consistent with assessed PRC-state tolerance of MSS-affiliated cluster moonlighting. No formal US, UK, or EU government attribution to a specific PRC ministry or unit has been published for APT27.

the MSS-aligned framing rests on vendor research and should be treated as suspected rather than formally confirmed.

Motivations
espionage, intelligence_gathering, geopolitical_collection, economic_intelligence, defense_industrial_collection, dissident_surveillance, religious_organization_surveillance, financial_gain, ransomware_operations
Sectors
Regions

Detection Blind Spots

60 techniques
Across this actor’s 60 mapped techniques, the share covered by each detection layer. Low bars are where you’d be blind if this actor targeted you.
Behavioral / log (Sigma)56/60 · 93%
Analytics (MITRE CAR)32/60 · 53%
Runtime / container (Falco)6/60 · 10%
File / malware (YARA)0/60 · 0%
Network (Suricata/Snort)16/60 · 26%
Vuln scan (Nuclei)0/60 · 0%

Atomic Test Plan

30 techniques
Runnable Atomic Red Team tests covering this actor’s mapped techniques - validate your detections against this specific adversary. Cross-reference the blind spots above. For authorized lab / purple-team use. Open the full builder

Tools Used

4 mapped
Other tooling / TTPs (curation, not ATT&CK-mapped):
MSHTASHARPHOUND
Intelligence Graph · click any node to traverse
CVETechnique ActorTool Family
drag to reposition · click any node to traverse · button top-right enlarges
External lookups - second-class, for what we don’t hold ourselves
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh  ·  Open-source threat intelligence platform  ·  100+ authoritative sources  ·  Every fact traces to its origin