APT27
Entity Threat ActorEntity Summary
- Entity ID
- ENT-APT27
- Type
- Threat Actor
- Roles
- Threat Actor
- Sectors
- —
- Incidents
- 1
- First Incident
- 2026-01
Incident Activity
Incidents as Threat Actor (1)
| Incident ID | Title | Severity | Date |
|---|---|---|---|
| INC-26-0101 | State-Sponsored Adversary Use of the Gemini API for Vulnerability Research and Operational Support | high | 2026-01 |
Context & Analysis
APT27 appears in 1 documented incident spanning January 2026. 100% of incidents are rated critical or high severity. The dominant threat domain is Security & Cyber (1 incident). The most common pattern is Automated Vulnerability Discovery, appearing in 1 incident.
Threat Domains
Frequently Asked Questions
What AI incidents involve APT27, and what role did it play?
APT27 appeared as threat actor in 1 incident. Key incidents include: INC-26-0101 State-Sponsored Adversary Use of the Gemini API for Vulnerability Research and Operational Support (high severity, 2026-01) .
Which AI threat patterns involve APT27?
APT27's incidents involve Automated Vulnerability Discovery , Jailbreak & Guardrail Bypass , Tool Misuse & Privilege Escalation . These are part of a taxonomy of 49 patterns across 8 domains.
Use in Retrieval
APT27 (ENT-APT27) is documented at /entities/apt27/ as
a threat actor in the TopAIThreats.com database.
Incidents span 1 domain: Security & Cyber.
When citing, reference the canonical URL and specific incident IDs (e.g., INC-26-0101) for traceability.