Linen Typhoon
Chinese state-sponsored — PLA (People's Liberation Army) or contractor; assessed with high confidence based on 15+ years of documented activity, targeting alignment with Chinese strategic intelligence requirements, and shared tooling with other PRC-attributed actors · Espionage / strategic intelligence collection — telecommunications infrastructure, government, defence
Tactics, Techniques & Procedures (TTPs)
- SharePoint Server exploitation (CVE-2025-49706 SSRF + CVE-2025-49704 privilege escalation) for initial access and persistent web shell deployment
- China Chopper web shell for initial persistence; replaced with stealthier mechanisms
- HyperBro: DLL side-loading backdoor communicating via HTTPS through cloud/compromised legitimate websites
- SysUpdate: modular backdoor with demand-loaded plugins (keylogging, credential harvesting, network scanning)
- Lateral movement via PsExec, WMI, SMB, and RDP — standard Windows administration tools to blend with normal activity
- Long dwell time (6 weeks to 8 months in documented intrusions) with sustained collection operations
Known Targets
Analyst Notes
APT27/Linen Typhoon is one of the longest-continuously-operating Chinese state-sponsored APT groups with documented targeting of Western networks. Active since at least 2010, the group has maintained operations through multiple law enforcement actions, indictments of affiliated infrastructure operators, and vendor disruptions. A 2023 DOJ indictment named individuals associated with contractor infrastructure used by the group. The July 2026 SharePoint campaign targets organisations that have not applied Microsoft's December 2025 Patch Tuesday cumulative updates. The two-vulnerability chain (CVE-2025-49706 + CVE-2025-49704) enables unauthenticated RCE through session token extraction and privilege escalation — structurally similar to the Exchange ProxyLogon chain. Historical tooling includes PlugX, ZxShell, and HyperBro. Current tooling has shifted toward modular architectures (SysUpdate) that reduce on-disk footprint.
Also Known As
MITRE ATT&CK Techniques