APT-C-27

Aliases: GoldMouse, Golden RAT, ATK80

First seen
2014-11-01 00:00:00
Origin
SY
Primary motivation
espionage
Sophistication
advanced
Resource level
government
Actor type
nation-state
Profile updated
2026-07-07 11:56:44

Targeted industries: government-and-public-sector

Targeted regions: country_code:sy

Context

A threat actor which is ac tive since at least November 2014. This group launched long-term at tacks against organizations in the Syrian region using Android and Windows malwares. Its objective is the theft of sensitive information.

Reports & references

  • ti.360.net — Apt C 27 (Goldmouse): Suspected Target Attack Against The Middle East With Winrar Exploit En (report)
  • ti.360.net — Analysis Of Apt C 27 (report)
  • web.archive.org — 20180723 Cse Apt27 Syria V1 (report)

External references