APT27
As of 2026-07-19, APT27 is a China-nexus threat actor tracked by Threadlinqs Intelligence across 2 threats spanning vulnerability, apt. Also known as Linen Typhoon, Altered Spider. ATT&CK coverage spans 39 techniques across 15 tactics in 2 of 2 tracked threats. Most-observed techniques: T1027 (Obfuscated Files or Information), T1059 (Command and Scripting Interpreter), T1071 (Application Layer Protocol).
Also known as: Linen Typhoon, Altered Spider
ATT&CK techniques observed
- T1027 Obfuscated Files or Information — Stealth (formerly Defense Evasion) — observed in 2 of 2 tracked threats
- T1059 Command and Scripting Interpreter — Execution — observed in 2 of 2 tracked threats
- T1071 Application Layer Protocol — Command and Control — observed in 2 of 2 tracked threats
- T1078 Valid Accounts — Initial Access — observed in 2 of 2 tracked threats
- T1082 System Information Discovery — Discovery — observed in 2 of 2 tracked threats
- T1190 Exploit Public-Facing Application — Initial Access — observed in 2 of 2 tracked threats
- T1552 Unsecured Credentials — Credential Access — observed in 2 of 2 tracked threats
- T1588 Obtain Capabilities — Resource Development — observed in 2 of 2 tracked threats
- T1005 Data from Local System — Collection — observed in 1 of 2 tracked threats
- T1021 Remote Services — Lateral Movement — observed in 1 of 2 tracked threats
- T1041 Exfiltration Over C2 Channel — Exfiltration — observed in 1 of 2 tracked threats
- T1056 Input Capture — Credential Access — observed in 1 of 2 tracked threats
- T1068 Exploitation for Privilege Escalation — Privilege Escalation — observed in 1 of 2 tracked threats
- T1083 File and Directory Discovery — Discovery — observed in 1 of 2 tracked threats
- T1090 Proxy — Command and Control — observed in 1 of 2 tracked threats
Tracked threats
- Microsoft July 2026 Patch Tuesday: Two Actively Exploited Zero-Days in AD FS and SharePoint (CVE-2026-56155, CVE-2026-56164) — CRITICAL
- GTIG AI Threat Tracker (May 2026) — First AI-Developed Zero-Day Exploit (2FA Bypass), PROMPTFLUX/HONESTCUE/CANFAIL/LONGSTREAM/PROMPTSPY AI-Enabled Malware, and APT27/APT45/UNC2814/UNC5673/UNC6201/TeamPCP AI-Augmented Operations — HIGH
Related CVEs
CVE-2026-58644, CVE-2026-57092, CVE-2026-56190, CVE-2026-56188, CVE-2026-56164, CVE-2026-56155, CVE-2026-55944, CVE-2026-55010, CVE-2026-55008, CVE-2026-54992, CVE-2026-54128, CVE-2026-54127, CVE-2026-50680, CVE-2026-50661, CVE-2026-50655, CVE-2026-50522, CVE-2026-50518, CVE-2026-50444, CVE-2026-50392, CVE-2026-50370, CVE-2026-50327, CVE-2026-42982