APT27
A China-based actor that targets foreign embassies to collect data on government, defence, and technology sectors.
APT27 is a China-based threat actor known for targeting government and defense sectors via Spearphishing.
APT27, also known as GreedyTaotie, is a China-based threat actor. This group primarily targets government, technology, and defense sectors in the United States, United Kingdom, France, Japan, Taiwan, India, and other countries, with a focus on foreign embassies. Their key TTPs include initial access via Spearphishing Attachment, deployment of Web Shells for persistence, credential theft from LSASS Memory using Mimikatz, and exfiltration to cloud storage. Defenders should prioritize detection of PlugX, Cobalt Strike, and other associated malware, as well as monitor for lateral movement techniques such as Windows Remote Management and data exfiltration attempts.
A China-based actor that targets foreign embassies to collect data on government, defence, and technology sectors.
Monitor file upload activity to detect suspicious malware uploads.
Detect exploit attempts on public-facing applications and spearphishing attachments.
Monitor scheduled task logs to detect suspicious At command executions.
Monitor web server logs and suspicious files to detect web shells.
Monitor privilege escalation logs to detect exploitation attempts and UAC bypass activity.
Monitor process creation and modification events to detect suspicious process hollowing.
Monitor access to LSASS process to detect credential theft from LSASS memory.
Monitor network scans and service discovery to detect network service discovery.
Monitor Windows Remote Management (WinRM) activity and detect suspicious WinRM connections.
Monitor file system access and file modifications to detect local data staging.
Monitor network traffic and file transfers to detect suspicious ingress tool transfer.
Monitor large data transfers and exfiltration to cloud storage to detect suspicious data exfiltration.
Monitor Windows Event Log activity to detect disabling or modification of Windows Event Log.
APT27, also known as GreedyTaotie, is a China-based threat actor. They primarily target government, technology, and defense sectors in the United States, United Kingdom, France, Japan, Taiwan, India, and other countries, with a focus on foreign embassies.
APT27 steals credentials from LSASS Memory using Mimikatz.
Every claim on this page is drawn from the cited source (MISP Galaxy, MITRE ATT&CK, ransomware.live) — no attribution is invented.