A China-based actor that targets foreign embassies to collect data on government, defence, and technology sectors....

Threat Actor Profile

APT27

State-sponsored threat group originating from CN. Suspected sponsor: Unknown. Known to target Government, Private sector.

2 Industries Tracked Real-Time Alerts

Actor Overview

Origin Country
CN
Suspected Sponsor
Unknown
Incident Types
Espionage

Target Industries

GovernmentPrivate sector

Suspected Victims

United StatesUnited KingdomFranceJapanTaiwanIndiaCanadaChinaThailandIsraelAustraliaRepublic of KoreaRussiaIranTurkey

Related Threat Reports

Premium
APT Campaign Analysis - Q4 2025Dec 2025
New Tactics Observed in WildDec 2025
Infrastructure Mapping ReportDec 2025
Stay Updated

Get alerts when new intel on APT27 is published.

Actor Details

Primary Name
APT27
Known Aliases
GreedyTaotie, TG-3390, EMISSARY PANDA, TEMP.Hippo, Red Phoenix, Budworm, Group 35, ZipToken, Iron Tiger, BRONZE UNION, Lucky Mouse, G0027, Iron Taurus, Earth Smilodon
Data Source
Precursor Intelligence
Need API Access?

Integrate threat actor data into your SIEM or SOAR.

View Plans →