ViciousPanda is a threat actor name referenced in reporting on APT activity and vendor naming practices. The available content indicates that Kaspersky assessed, based on OSINT, that ViciousPanda was among the APT actors using COVID-19-themed lures during Q1 2020, alongside Kimsuky, APT27, and Lazarus. The content does not provide high-confidence details on ViciousPanda’s specific targets, malware, infrastructure, or core TTPs beyond that use of COVID-19-themed social-engineering lures. The name is also cited as an example of a threat group moniker used by vendors following CrowdStrike-style naming conventions. No additional confirmed aliases, sub-groups, or attribution details are provided in the content.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
1 malware family attributed to this actor across reporting.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
ViciousPanda is a threat group named by vendors such as Checkpoint, Kaspersky, and ClearSky, not CrowdStrike. No specific activity is described in this content.
Referenced as using COVID-19-themed lures; no additional operational detail provided in this text.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.