Home
Glossary
APT27 (LuckyMouse, EmissaryPanda)
Table of content
5 min
H2 title on one or more lines.
Share
By
Updated on
June 22, 2026

APT27 (LuckyMouse, EmissaryPanda)

APT27, also known as LuckyMouse or Emissary Panda, is a Chinese advanced persistent threat group active since at least 2010, known for long-term espionage campaigns and data theft across government, defense, financial, and energy sectors.

APT27, also known as LuckyMouse or Emissary Panda, is a Chinese advanced persistent threat (APT) group. It has been active since at least 2010 and has targeted a broad range of sectors including government, defense, financial, energy, and legal services. The group is known for its long-term espionage campaigns and data theft operations.

APT27 is notable for its use of a backdoor application targeting MacOS, as detailed in a Sekoia.io analysis. This shows the group's adaptability and ongoing threat across different operating systems.

In another analysis, Sekoia.io describes an incident response to detection engineering case involving APT27 (Lucky Mouse), demonstrating the real-world impact of this threat actor.

We are a cybersecurity software publisher. We provide SOC and MSSP teams with a turnkey operational security platform (SOC platform). Through our XDR platform, CTI tool and threat intelligence platform, we enable our users to neutralize cyber threats, regardless of the attack surface.