APT-C-27
A threat actor which is ac tive since at least November 2014. This group launched long-term at tacks against organizations in the Syrian region using Android and Windows malwares. Its objective is the theft of sensitive information.
APT-C-27 targets organizations in the Syrian region using Android and Windows malware for data theft since 2014.
APT-C-27 (GoldMouse, Golden RAT, ATK80) has been active since at least November 2014. The group primarily targets organizations in the Syrian region. Their objective is the theft of sensitive information, employing both Android and Windows malwares. Defenders should focus on detecting suspicious application permissions on mobile platforms and anomalous network traffic on Windows systems, given the actor's long-term attack patterns.
A threat actor which is ac tive since at least November 2014. This group launched long-term at tacks against organizations in the Syrian region using Android and Windows malwares. Its objective is the theft of sensitive information.
APT-C-27 employs malware targeting both Android and Windows operating systems.
Defenders should focus on anomalous network traffic on Windows systems.
Every claim on this page is drawn from the cited source (MISP Galaxy, MITRE ATT&CK, ransomware.live) — no attribution is invented.