Threat Intelligence / Actor / APT27

APT27

As of 2026-07-19, APT27 is a China-nexus threat actor tracked by Threadlinqs Intelligence across 2 threats spanning vulnerability, apt. Also known as Linen Typhoon, Altered Spider. ATT&CK coverage spans 39 techniques across 15 tactics in 2 of 2 tracked threats. Most-observed techniques: T1027 (Obfuscated Files or Information), T1059 (Command and Scripting Interpreter), T1071 (Application Layer Protocol).

Nation: China · 2 tracked threat(s) · Categories: VULNERABILITY, APT

Also known as: Linen Typhoon, Altered Spider

ATT&CK techniques observed

39 techniques observed across 2 of 2 tracked threats · Command and Control (5), Credential Access (5), Initial Access (4), Resource Development (4), Stealth (formerly Defense Evasion) (4), Discovery (3)

Tracked threats

Related CVEs

22 CVEs referenced by tracked APT27 activity

CVE-2026-58644, CVE-2026-57092, CVE-2026-56190, CVE-2026-56188, CVE-2026-56164, CVE-2026-56155, CVE-2026-55944, CVE-2026-55010, CVE-2026-55008, CVE-2026-54992, CVE-2026-54128, CVE-2026-54127, CVE-2026-50680, CVE-2026-50661, CVE-2026-50655, CVE-2026-50522, CVE-2026-50518, CVE-2026-50444, CVE-2026-50392, CVE-2026-50370, CVE-2026-50327, CVE-2026-42982

Full actor intelligence — infrastructure, IOCs, detection coverage and operator fingerprints — is available via the Threadlinqs MCP server (Purple tier). View plans →

Threadlinqs Intelligence