APT-C-27
Aliases: GoldMouse, Golden RAT, ATK80
- First seen
- 2014-11-01 00:00:00
- Origin
- SY
- Primary motivation
- espionage
- Sophistication
- advanced
- Resource level
- government
- Actor type
- nation-state
- Profile updated
- 2026-07-07 11:56:44
Targeted industries: government-and-public-sector
Targeted regions: country_code:sy
Context
A threat actor which is ac tive since at least November 2014. This group launched long-term at tacks against organizations in the Syrian region using Android and Windows malwares. Its objective is the theft of sensitive information.
Reports & references
- ti.360.net — Apt C 27 (Goldmouse): Suspected Target Attack Against The Middle East With Winrar Exploit En (report)
- ti.360.net — Analysis Of Apt C 27 (report)
- web.archive.org — 20180723 Cse Apt27 Syria V1 (report)