APT PRC State-Sponsored Active since 2010

APT27

Espionage targeting government, defense, technology. Known for SysUpdate RAT and HyperBro backdoor.

Scroll

APT27 is a PRC state-sponsored espionage group active since at least 2010, targeting government agencies, defense contractors, and technology companies worldwide. The group is known for its custom tooling including SysUpdate RAT, HyperBro backdoor, and exploitation of web-facing applications for initial access.

AttributeDetail
NamesAPT27 / Emissary Panda / Lucky Mouse
AttributionPRC State-Sponsored
Active Since2010
Primary FocusEspionage targeting government, defense, technology. Known for SysUpdate RAT and HyperBro backdoor.

Overview

APT27 is a PRC state-sponsored espionage group active since at least 2010, targeting government agencies, defense contractors, and technology companies worldwide. The group is known for its custom tooling including SysUpdate RAT, HyperBro backdoor, and exploitation of web-facing applications for initial access.

Attribution

APT27 / Emissary Panda / Lucky Mouse is attributed to PRC State-Sponsored, active since at least 2010. Espionage targeting government, defense, technology. Known for SysUpdate RAT and HyperBro backdoor.

Notable Campaigns

MITRE ATT&CK Mapping

Technique IDTechniqueConfidence
T1190Exploit Public-Facing ApplicationHigh
T1059Command and Scripting InterpreterHigh
T1105Ingress Tool TransferHigh
T1071Application Layer ProtocolHigh
T1036MasqueradingHigh

Detection & Defense

Recommended Defenses

Monitor for the TTPs listed above using your SIEM and EDR platforms. Prioritize patching of internet-facing applications and enforce MFA on all remote access. Mjolnir Security provides continuous threat hunting and monitoring for APT27 activity patterns.

Mjolnir Security — Threat Intelligence & Response

Mjolnir Security provides 24/7 threat monitoring, incident response, and threat intelligence services. Contact us for threat hunting specifically targeting APT27 TTPs in your environment.

Threat Hunting Incident Response Threat Intelligence SOC-as-a-Service

mjolnirsecurity.com — 24/7 Incident Response Hotline: +1 833 403 5875