Sharp Panda is a China-linked state-sponsored espionage threat actor primarily associated with operations against governments, public-sector entities, and organizations in Southeast Asia, with observed activity extending to Malaysia and other regional targets. The group is also referred to as SharpPanda and has been renamed Sharp Dragon by Check Point to reduce naming ambiguity. Open-source reporting consistently places the actor within the broader ecosystem of Chinese cyber-espionage operations. Sharp Panda is known for targeted intrusion activity focused on intelligence collection. Its tradecraft emphasizes system information discovery and broad host reconnaissance before follow-on actions. Observed malware attributed to the group has collected hostnames, operating system details, usernames, network interface information, installed software, and running processes, then encrypted and encoded the results for command-and-control transmission. Reported tooling includes backdoor and loader functionality designed to establish persistent access and support subsequent payload delivery. Recent reporting describes a shift in delivery and execution tradecraft. Sharp Panda has historically been associated with RoyalRoad-style document lures and Microsoft Word Equation Editor exploitation, but newer activity shows use of a dedicated dropper disguised as a document to deploy the 5.t framework. This dropper attempts to load malicious DLLs already present on disk, can write a next-stage payload disguised as a benign file type, drops a decoy document to reduce suspicion, and establishes persistence through scheduled tasks created via COM interfaces. Analysis of the same tooling also identified concealed strings, API hashing, and unused or untriggered capabilities consistent with spyware-oriented functions such as keylogging and screenshot capture. Across reporting, Sharp Panda’s operational patterns align with common Chinese espionage tradecraft: spearphishing or document-based lures, staged malware deployment, extensive host profiling, stealth through obfuscation and masquerading, use of application-layer protocols for command and control, and persistence via scheduled tasks. The actor’s campaigns are best understood as long-term intelligence-gathering operations rather than disruptive or financially motivated activity.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
16 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 malware family attributed to this actor across reporting.
4 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Listed among detected threat actors/TTP references, but not substantively discussed in the report summary.
Chinese-linked intrusion set using a new dropper/loader to deploy the 5.t framework, dropping a malicious DLL disguised as an .ini file, creating a scheduled task for persistence, and historically relying on RoyalRoad in campaigns targeting Southeast Asia.
Espionage-style malware activity targeting Malaysia in March-April 2024 using a malicious executable that establishes a backdoor/C2 connection, collects host information, encrypts it, and sends it to attacker infrastructure.
Performs extensive system information discovery and reconnaissance prior to targeted attacks; uses a loader/downloader to collect host data.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.