Skip to main content
Mallory
🇭🇰 🇯🇵 🇺🇸 🇮🇳 HK5 malware families

APT-Q-27

Also known asapt_q_27

APT-Q-27, also known as GoldenEyeDog and Dragon Breath, is a Chinese-nexus threat group that has been active since at least 2022. Reporting in the provided content links the group to campaigns targeting gambling, cryptocurrency, and Web3 organizations, including customer support teams. In one active campaign, the group posed as customers in live support chats and sent fake screenshot shortlinks that delivered a .pif executable disguised as an image. The malware chain used a multi-stage design: retrieval of additional components from an AWS S3 bucket via a manifest, DLL sideloading using a legitimate YY platform binary (updat.exe), decryption and in-memory execution of payloads from files such as yyext.log or updat.log, and a final persistent backdoor. Observed persistence and defense-evasion behaviors included registry Run keys, Windows service creation including the misspelled service name "Windows Eventn.", registry modifications, UAC disabling through three registry keys, obfuscated executables, reflective or in-memory loading, and cleanup activity. The implant communicated over TCP port 15628 with 37 hardcoded command-and-control servers in one campaign. Runtime artifacts associated with the group in the content include the mutex Global\DHGGlobalMutex and registry keys HKCU\offlinekey\open and HKCU\offlinekey\clipboard; the latter are described as settings related to keylogging and clipboard hijacking. Additional reporting ties APT-Q-27 to the long-running sims-4-updater malware campaign, including a 2026 sample signed with a DigiCert EV code-signing certificate issued to MobSoft Co., Ltd, using live infrastructure such as lightindividual.com and dead-drop resolvers on rentry.co, rentry.org, and gist.githubusercontent.com. CyStack also reported a mid-January 2026 intrusion in a corporate customer support environment whose command-and-control infrastructure, modular backdoor design, multi-stage architecture, and use of an encrypted payload container resembled prior APT-Q-27 activity, though that attribution was not definitive.

Share:
Are they targeting you?

Know when an actor pivots toward your sector

Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.

OPERATIONAL PROFILE

Targeting

Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.

Who they target

Sectors the actor has been observed targeting.

  • Commercial & Professional Services

Where they're from

Attributed origin per open-source reporting.

  • HK
  • JP
  • US
  • IN
MITRE ATT&CK

Tradecraft

36 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.

12 of 15 tactics58 techniques×N= number of intelligence reports citing this technique
MITRE ATT&CK
TA0042
Resource Development
1 technique
T1583
Acquire Infrastructure
T1583.001
Domains
T1583.003
Virtual Private Server
TA0001
Initial Access
3 techniques
T1189×2
Drive-by Compromise
T1195
Supply Chain Compromise
T1566
Phishing
T1566.001
Spearphishing Attachment
T1566.002×3
Spearphishing Link
TA0002
Execution
4 techniques
T1059
Command and Scripting Interpreter
T1059.007
JavaScript
T1129
Shared Modules
T1204
User Execution
T1204.002
Malicious File
T1574
Hijack Execution Flow
T1574.001×2
DLL
TA0003
Persistence
3 techniques
T1112×3
Modify Registry
T1543
Create or Modify System Process
T1543.003×2
Windows Service
T1547
Boot or Logon Autostart Execution
T1547.001×3
Registry Run Keys / Startup Folder
TA0004
Privilege Escalation
4 techniques
T1055
Process Injection
T1055.001
Dynamic-link Library Injection
T1543
Create or Modify System Process
T1543.003×2
Windows Service
T1547
Boot or Logon Autostart Execution
T1547.001×3
Registry Run Keys / Startup Folder
T1548
Abuse Elevation Control Mechanism
T1548.002
Bypass User Account Control
TA0005
Stealth
7 techniques
T1027
Obfuscated Files or Information
T1027.007
Dynamic API Resolution
T1036×4
Masquerading
T1036.004
Masquerade Task or Service
T1055
Process Injection
T1055.001
Dynamic-link Library Injection
T1070
Indicator Removal
T1070.001
Clear Windows Event Logs
T1140×2
Deobfuscate/Decode Files or Information
T1574
Hijack Execution Flow
T1574.001×2
DLL
T1620×3
Reflective Code Loading
TA0112
Defense Impairment
2 techniques
T1112×3
Modify Registry
T1553
Subvert Trust Controls
T1553.002×3
Code Signing
TA0006
Credential Access
2 techniques
T1056
Input Capture
T1056.001
Keylogging
T1649
Steal or Forge Authentication Certificates
TA0007
Discovery
1 technique
T1082
System Information Discovery
TA0009
Collection
2 techniques
T1056
Input Capture
T1056.001
Keylogging
T1115×2
Clipboard Data
TA0011
Command and Control
4 techniques
T1071×2
Application Layer Protocol
T1071.001
Web Protocols
T1102
Web Service
T1102.001
Dead Drop Resolver
T1105×3
Ingress Tool Transfer
T1568
Dynamic Resolution
T1568.002
Domain Generation Algorithms
TA0040
Impact
1 technique
T1529
System Shutdown/Reboot
IOCS

Observables

100 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.

IOC values are gated. View more in Mallory for domains, IPs, hashes, and other artifacts, or pipe them straight into your SIEM.

ACTIVITY FEED

Recent activity

3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.

What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: sector and geo overlap with your footprint, the IOCs they’re burning right now, detection coverage, and what to do next.
Target overlap

Match sector + geo + tech-stack targeting against your real footprint.

Tradecraft mapping36

Every observed MITRE ATT&CK technique, grouped by tactic.

Malware arsenal5

Families this actor is known to deploy, with IOCs and behavior.

Exploited CVEs

CVEs this actor has used in known campaigns.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

Observables100

Domains, IPs, and hashes tied to this actor, refreshed continuously.