APT27 (as knownLuckyMouse, EmissaryPanda) threat actor
APT27 is a China-nexus cyber espionage group active since at least 2010, known for long-running intrusions that steal information from government and industry targets around the world. It is widely assessed to be Chinese state-sponsored, and it is tracked under a large number of names, most commonly Emissary Panda, LuckyMouse, and Iron Tiger. MITRE ATT&CK catalogs it as G0027. Over more than a decade the group has built a broad toolset and a reputation for getting into a network and staying there, sometimes undetected for months or years. APT27 is a patient, access-focused actor rather than a smash-and-grab one. It typically breaks in through internet-facing web applications, establishes a quiet foothold, and works to expand access and collect intelligence over the long term. This page covers the group's attribution and aliases, who it targets, how it operates, its malware and notable campaigns, and how organizations defend against it, drawing in part on first-party research by Sekoia's Threat Detection & Research (TDR) team.
Key takeaways
- APT27 is a China-nexus espionage group, active since at least 2010 and widely assessed to be Chinese state-sponsored.
- It has many names. Emissary Panda, LuckyMouse, Iron Tiger, Bronze Union, Budworm, and TG-3390 all refer to the same actor, tracked by MITRE as G0027.
- It targets government and strategic industry, including defense, aerospace, telecom, energy, technology, manufacturing, and diplomatic bodies worldwide.
- It favors web-application exploitation and long dwell time. The group breaks in through internet-facing servers and often remains undetected for extended periods.
- HyperBro and other custom malware are its signature, alongside cross-platform tooling that has reached Windows, Linux, and macOS.
Attribution and aliases
APT27 is widely assessed by the security industry to be a Chinese state-sponsored group, based on more than a decade of targeting aligned with Chinese strategic interests, shared malware and infrastructure across campaigns, and analysis by numerous vendors. Its espionage focus and long-term intelligence collection are consistent with a state-directed mission rather than financially motivated crime, although the group has at times been linked to activity with a financial dimension.
Because so many teams have tracked the group independently, it carries an unusually long list of names. The most common are below:
- APT27
- TEMP.Hippo
- Emissary Panda
- LuckyMouse / Lucky Mouse
- Iron Tiger
- Bronze Union
- TG-3390
They all point to the same actor. As with other long-running groups, some overlap and occasional disagreement between vendor clusters is normal, so analysts cross-reference reporting when researching it. A note on scope: this China-nexus APT27 is unrelated to groups that share the number in other naming schemes, and the aliases above are the ones consistently mapped to this actor.
Who APT27 targets
APT27's targeting is broad but consistent, concentrating on organizations that hold information of strategic value. Its usual targets include:
- Government and diplomatic bodies, a recurring focus across many countries and regions.
- Defense and aerospace, including contractors and subcontractors in the supply chain.
- Critical and strategic industry, such as energy, telecommunications, manufacturing, and technology.
- Other high-value sectors, including financial and legal services, and research and education.
Geographically the group has operated across North America, Europe, the Middle East, and the Asia-Pacific region, going wherever a target holds information relevant to its mission. Notably, Sekoia's research identified a campaign that appeared aimed at surveillance of users inside China, suggesting the group's remit can extend to domestic monitoring as well as foreign espionage.
How APT27 operates
APT27's approach is methodical and built for persistence. Its activity maps cleanly onto the MITRE ATT&CK framework.
On the malware side, the group's best-known tool is HyperBro, a remote access trojan used for reconnaissance, command execution, and control of compromised hosts. Its wider toolset has included PlugX and SysUpdate (both remote access trojans widely used across China-nexus groups), ShadowPad (a modular backdoor), QuarkBandit, and Mirage. APT27 has also shown notable cross-platform reach: while historically Windows-focused, the group has developed Linux and macOS implants, including an rshell backdoor delivered through a trojanized chat application, which Sekoia documented in 2022.
Notable campaigns and activity
Across its long history, APT27 has been tied to a series of espionage operations:
- TG-3390 web compromises. Early reporting documented the group compromising strategically chosen websites and web servers to reach its intended targets.
- Zoho ManageEngine exploitation. From 2021, the group breached servers running vulnerable Zoho ManageEngine software to deploy HyperBro and other implants.
- The MiMi chat-application backdoor (2022). Sekoia and Trend Micro documented a trojanized chat app delivering the rshell backdoor to macOS and Linux, an unusual cross-platform and possible domestic-surveillance campaign.
- Ongoing intrusions. The group has continued to be linked to espionage against government and industry targets in more recent reporting, reflecting a still-active operation.
How to defend against APT27
Because APT27 relies on exploiting exposed applications and then hiding in a network for the long term, defense centers on attack-surface hygiene and behavioral detection:
- Patch internet-facing systems quickly. Since the group's initial access depends on vulnerable web applications such as Exchange, SharePoint, and Zoho ManageEngine, prompt patching closes its main entry point.
- Reduce and monitor the external attack surface. Inventory internet-facing services, remove what is not needed, and watch exposed applications closely for exploitation attempts and web shells.
- Hunt for persistence and lateral movement. Monitor for web shells, DLL sideloading, scheduled tasks, and unusual internal reconnaissance, which are the behaviors that reveal a long-dwell intrusion.
- Cover all platforms. Because the group has reached Windows, Linux, and macOS, detection should extend across every operating system in the environment, not just Windows.
- Use threat intelligence. Tracking APT27's known tooling, infrastructure, and current techniques helps teams recognize its activity in context and prioritize the sectors and systems it targets.
Sekoia's research on APT27
Sekoia's TDR team has investigated APT27 directly, which is part of why the group is well understood on the platform. In 2022, while reviewing command-and-control infrastructure tied to the group's HyperBro trojan, TDR discovered that a Chinese-language chat application had been backdoored to deliver an rshell implant to macOS, the first time Sekoia observed this actor targeting that operating system and a possible sign of an expansion toward surveillance. In a separate analysis, Sekoia documented an incident-response case involving APT27 alongside a managed-security partner, and turned the observed techniques into detection rules, publicly sharing the logic behind them. This kind of first-hand investigation is what turns a name in a report into an actor a defender can actually recognize and detect.
Expert insight: An actor built for the long game
What makes APT27 dangerous is not a single clever exploit but its patience. The group gets in through an exposed application, establishes persistence without drawing attention, and then operates over months or years, blending its activity into normal network traffic. There is rarely a dramatic moment to catch; instead there is a slow accumulation of small, individually unremarkable actions, a web shell here, a scheduled task there, an encrypted outbound connection that looks ordinary. That is exactly the kind of intrusion that evades tools looking at one event at a time.
This is where a CTI-led approach earns its place. Sekoia is a European cybersecurity vendor whose in-house TDR team tracks China-nexus actors such as APT27, and that intelligence, known tooling, infrastructure, and technique patterns, feeds the platform so the group's activity is recognized in context. Rather than treating a web-shell alert or an unusual connection as isolated noise, Sekoia's SOC platform correlates signals across endpoint, network, and cloud and maps them to the MITRE ATT&CK framework, so that exploitation leading to persistence and command-and-control can be seen as one long-running intrusion. Sekoia's own detection engineering against APT27, built from a real incident, is an example of turning first-hand intelligence into deployable detection.
The practical takeaway for defenders is that an actor this patient is caught through breadth and continuity of visibility, not through any single alert. Prevention such as patching exposed applications is essential and will stop many attempts, but the intrusions that succeed are the ones that look ordinary and persist, and those surface only when telemetry from every platform is read together, over time, against current intelligence. As a European vendor with a data-sovereignty posture, Sekoia is built for that kind of cross-surface, long-horizon detection.