Budworm, also known as APT27 and Linen Typhoon, is a China-linked cyberespionage group targeting strategically significant government and commercial organizations. Its confirmed targets include a Middle Eastern government, a U.S. state legislature, a multinational electronics manufacturer, and a hospital in Southeast Asia. Its operations have focused on Asia, the Middle East, and Europe, alongside historical and renewed targeting of U.S. organizations. Budworm exploits vulnerable internet-facing applications for initial access. It has exploited Apache Log4j vulnerabilities to compromise Apache Tomcat services and install web shells. In July 2025, it was identified as one of the China-linked actors exploiting the Microsoft SharePoint ToolShell vulnerability, CVE-2025-53770, before patching. The group's principal malware payload is HyperBro, frequently deployed through DLL sideloading using legitimate CyberArk Viewfinity software. It also uses PlugX, alternatively known as Korplug, and Cobalt Strike for post-exploitation. Its supporting tools include LaZagne for credential theft, Fscan for internal network scanning, and IOX and Fast Reverse Proxy for proxying and port forwarding. Its tradecraft combines exploitation of public-facing services, credential dumping, internal reconnaissance, and abuse of legitimate applications to load malicious payloads. Budworm uses rented virtual private servers for command-and-control infrastructure.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
8 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
6 malware families attributed to this actor across reporting.
1 additional family tracked in Mallory.
3 CVEs this actor has used in observed campaigns. 3 of them exploited in the wild.
Attackers deploying Warlock were discovered exploiting the ToolShell zero-day vulnerability in Microsoft SharePoint (CVE-2025-53770) on July 19, 2025. Storm-2603 used the exploit to deploy Warlock and LockBit ransomware.
In recent attacks, Budworm leveraged the Log4j vulnerabilities (CVE-2021-44228 and CVE-2021-45105) to compromise the Apache Tomcat service on servers in order to install web shells.
In recent attacks, Budworm leveraged the Log4j vulnerabilities (CVE-2021-44228 and CVE-2021-45105) to compromise the Apache Tomcat service on servers in order to install web shells.
39 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
China-linked actor reported by Microsoft as exploiting the ToolShell SharePoint zero-day (CVE-2025-53770).
Chinese espionage group explicitly identified by Microsoft as exploiting the ToolShell vulnerability.
Mentioned as another China-linked actor exploiting the SharePoint ToolShell vulnerability before patching. The reference does not attribute Warlock deployment to Budworm.
Chinese APT group mentioned as a TTP comparison. The report does not attribute the observed campaign to Budworm, so the campaign's tools, vulnerabilities, and targets cannot be assigned to this group.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.