APT27, also known as Budworm and Linen Typhoon, is a China-linked espionage threat actor. The group has been identified exploiting Microsoft SharePoint ToolShell vulnerabilities in 2025 as part of post-compromise operations against government and telecommunications targets. Reported victimology includes a telecommunications company in the Middle East, government departments in Africa, government agencies in South America, and a university in the United States, indicating broad geographic targeting consistent with intelligence collection. Observed tradecraft includes rapid exploitation of newly disclosed vulnerabilities for initial access, deployment of webshells and modular backdoors, DLL sideloading, credential theft, privilege escalation, lateral movement, and persistence. Malware and tooling associated with these intrusions included Zingdoor, ShadowPad, KrustyLoader, Sliver, and credential-dumping and proxy utilities. The actor has also been observed abusing SQL servers and Apache HTTP servers running Adobe ColdFusion for malware delivery in some compromises. Operational behavior suggests selective follow-on exploitation after broader scanning and access activity. In Microsoft tracking, Budworm/Linen Typhoon was one of multiple China-linked espionage actors exploiting ToolShell, alongside Sheathminer/Violet Typhoon and Storm-2603. High-confidence reporting in this context supports Budworm as an espionage-focused actor rather than a ransomware operator. Known aliases include Budworm and Linen Typhoon; APT27 is a widely used industry designation.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Attributed origin per open-source reporting.
8 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
5 malware families attributed to this actor across reporting.
3 CVEs this actor has used in observed campaigns. 3 of them exploited in the wild.
China-based attackers used the ToolShell vulnerability (CVE-2025-53770) to compromise a telecoms company in the Middle East shortly after the vulnerability was publicly revealed and patched in July 2025... ToolShell affects on-premise SharePoint servers and gives an attacker unauthenticated access to vulnerable servers, allowing them to remotely execute code and access all content and file systems.
In late 2022, APT27 (also tracked as “Budworm”) exploited high-severity Log4j vulnerabilities (CVE‑2021‑44228 and CVE‑2021‑45105) to infect systems running Apache Tomcat and install web shells.
In late 2022, APT27 (also tracked as “Budworm”) exploited high-severity Log4j vulnerabilities (CVE‑2021‑44228 and CVE‑2021‑45105) to infect systems running Apache Tomcat and install web shells.
1 indicator attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
China-linked actor reported by Microsoft as exploiting the ToolShell SharePoint zero-day (CVE-2025-53770).
Chinese espionage group explicitly identified by Microsoft as exploiting the ToolShell vulnerability.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.