Netskope Threat Labs

LuckyMouse

ATP Sandbox Adv. HeuristicsAV

LuckyMouse (a.k.a. Emissary Panda and APT27) is a Chinese state sponsored threat group that targets governments and defense, engineering, and telecommunications organizations. Researchers have documented its use of custom backdoors, exploitation of internet facing servers, and abuse of legitimate administrative tooling.

First seen
April 2022
Last seen
September 2026
Alert Name
Dropped:Trojan.LuckyMouse.1
Linux.Trojan.LuckyMouse
Trojan.LuckyMouse.1
Win32.Infostealer.LuckyMouse
Win32.Trojan.LuckyMouse
Win64.Trojan.LuckyMouse