Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors Group 27

Also known as: Group 27, NIGHTSHADE PANDA, Red Pegasus, Nightshade Panda, APT9

Description

**Toolset/Malware:** Trochilus RAT, PlugX, EvilGrab, 3102 variant of 9002 RAT **Overlaps with:** Seven Pointed Dagger, Trochilus RAT

TTP Summary

Seven Pointed Dagger

Goals & Targeting

Targeted Sectors

Pharmaceutical
Healthcare
Construction
Aerospace
Defense
Energy
Aerospace & defense
Media
Transportation

AI Analysis

· 1 week ago

Executive Summary

Group 27, also known as NIGHTSHADE PANDA or Red Pegasus, is a high-sophistication nation-state threat actor primarily involved in espionage activities targeting critical sectors such as pharmaceuticals, healthcare, construction, aerospace, and defense. The group is known for its use of advanced malware like Trochilus RAT and PlugX, which suggests a focus on long-term, stealthy operations to collect sensitive information. Group 27's activities pose significant risks to global supply chains and national security.

Goals & Targeting

Group 27's primary goal appears to be intelligence gathering through espionage activities, targeting sectors and countries that hold significant economic or strategic value. The group's broad targeting across industries suggests a focus on accumulating sensitive information that could benefit the nation-state sponsor's interests. Typical victims include organizations in pharmaceuticals, healthcare, construction, aerospace, defense, energy, media, and transportation, which are critical to national security and global supply chains.

Enhanced Description

Group 27, often referred to as NIGHTSHADE PANDA or Red Pegasus, is a nation-state-sponsored threat actor with a primary focus on espionage. The group has demonstrated a high level of sophistication in its operations, leveraging advanced persistent threat (APT) tactics and tools to infiltrate target organizations. Known for its use of malware such as Trochilus RAT, PlugX, EvilGrab, and the 3102 variant of 9002 RAT, Group 27 has targeted a wide range of industries including pharmaceuticals, healthcare, construction, aerospace, defense, energy, media, and transportation. These sectors are likely chosen for their strategic importance and access to sensitive information that could benefit the nation-state sponsor. The group's operations often involve careful planning and execution, aiming to remain undetected while achieving its objectives.

Key Capabilities

  • Advanced persistent threat (APT) tactics
  • Use of sophisticated malware such as Trochilus RAT, PlugX, EvilGrab, and 3102 variant of 9002 RAT
  • Stealthy infiltration and long-term presence in target networks
  • Espionage operations aimed at collecting sensitive data

MITRE ATT&CK Tactics

Collection and Exfiltration
Defense Evasion
Credential Access
Lateral Movement
Intrusion Set-Up

ATT&CK Techniques

T1566.001
T1284
T1036.004
T1078.001
T1055
T1091

Software / Tooling

PlugX
Trochilus RAT
EvilGrab
3102 variant of 9002 RAT
Seven Pointed Dagger

Campaigns & Victims

Group 27 has been linked to several notable campaigns, including 'Agriculture in EU,' which indicates a focus on sectors with significant economic influence. The group's operations often overlap with other known APTs, such as Seven Pointed Dagger, suggesting potential collaboration or shared tactics within the broader threat landscape. Group 27's activities have been observed over an extended period, indicating a patient and methodical approach to achieving its objectives.

IOC Patterns

  • Use of custom malware for initial access and persistence
  • Phishing emails with malicious attachments
  • Network traffic anomalies indicative of C2 communication
  • Persistence mechanisms in compromised systems

Recommended Actions

  • Implement advanced email filtering to detect phishing attempts
  • Monitor network traffic for signs of C2 communication patterns
  • Conduct regular endpoint detection and response (EDR) activities
  • Patch and secure all known vulnerabilities in critical systems
  • Leverage threat intelligence feeds to identify potential Group 27 TTPs

Suggested Tags

APT
espionage
Nation-State
Sectors - Pharmaceuticals
Sectors - Healthcare

Confidence Assessment

Group 27 is a well-documented APT group with a significant presence in the threat landscape. The available data includes details on its toolset, targeting patterns, and overlaps with other groups. However, gaps exist regarding its exact origin and specific campaign activities in certain regions, which could impact the accuracy of some intelligence.

ATT&CK Techniques

No techniques linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

No IOCs linked yet.

References

No references recorded yet.

Intel Summary

0

Techniques

18

Tools

2

Campaigns

0

IOCs

0

Observed Data

0

Tactics

Tags

APT
Backdoor / C2
espionage
Nation-State
Sectors - Pharmaceuticals
Sectors - Healthcare

Details

MITRE ID
APT9
Type
Nation-State
Resource Level
Government
Primary Motivation
Espionage
Country of Origin
China (CN)
Confidence
70%
Added
May 4, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.