Aquatic Panda is a China-linked threat actor associated with cyber espionage activity in Latin America. Reported targeting has focused on government entities and telecommunications providers, aligning with broader Chinese strategic intelligence collection priorities in the region. The actor is assessed as part of the wider ecosystem of Chinese state-aligned intrusion activity that targets public-sector institutions, telecom infrastructure, and other strategically significant organizations to support geopolitical influence and long-term intelligence requirements. High-confidence public reporting in the available material identifies Aquatic Panda specifically as targeting a mix of government and telecom entities in Latin America. No additional aliases, malware families, or distinctive tradecraft are directly supported at high confidence in the available material beyond this targeting profile and China nexus.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
14 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
APT41, a China-backed advanced persistent threat group, has been observed conducting cyberattacks in Africa. The group is known for both espionage and financially motivated operations, and their activities in Africa likely include targeting government, technology, and financial sectors.
APT41 is a Chinese-linked threat actor targeting European governments, particularly in the maritime and shipping sectors.
Targets software vendors and gaming companies, embedding backdoors like ShadowPad into legitimate software updates for persistent access.
APT41 is conducting cyber espionage campaigns targeting U.S. government, think tanks, and academic organizations involved in U.S.-China trade and policy. Their operations include spearphishing, impersonation of officials, and the use of sophisticated malware and legitimate services to gain persistent access and exfiltrate sensitive data.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.