Panda is a threat actor name associated with at least two distinct clusters of malicious activity reflected in available reporting: a financially motivated cryptojacking operation tracked from 2018 to 2019, and malware code-base overlaps with an APT campaign targeting Vietnam. The strongest, directly supported body of evidence ties Panda to a large-scale illicit cryptocurrency mining campaign commonly associated with MassMiner activity. In the cryptomining operations, Panda exploited public-facing server vulnerabilities including CVE-2017-10271 in Oracle WebLogic, CVE-2017-5638 in Apache Struts 2, CNVD-2018-24942 in ThinkPHP, and later CVE-2019-2725 in Oracle WebLogic. The actor used internet-wide scanning to identify vulnerable systems, then retrieved miner payloads through PowerShell or certutil-based download chains. Post-compromise behavior included deployment of Monero miners, installation of auxiliary tooling, scheduled-task-based execution and persistence, firewall tampering, and modification of file permissions. Panda also demonstrated substantial post-exploitation capability. Observed tradecraft included SMB scanning, brute forcing, lateral movement, credential theft using Mimikatz, and use of exploit components associated with Shadow Brokers and EternalBlue-style propagation. Some infections additionally deployed Gh0st RAT, indicating the actor sometimes combined cryptomining with remote-access functionality. Victim profiling included use of Chinese-language IP geolocation services. The actor repeatedly rotated infrastructure while preserving broadly consistent tactics, techniques, and procedures. Confirmed victim sectors for Panda’s mining campaigns included banking, health care, transportation, telecommunications, and information technology services. Available evidence also links the Panda name to malware sharing a code base with an earlier campaign targeting Vietnam that used a weaponized RTF lure exploiting an Equation Editor vulnerability and a scheduled-task-executed DLL payload. However, the relationship between that Vietnam-focused activity and the MassMiner cryptojacking cluster is not sufficiently resolved here to treat them as a single fully unified intrusion set beyond the shared Panda attribution label. Available evidence supports a China nexus for Panda. The actor’s observed behavior and infrastructure registration details are consistent with operation by a Chinese-speaking threat actor. Panda is best characterized, on the strongest supported evidence, as a financially motivated intrusion actor focused on opportunistic exploitation of exposed enterprise services for cryptocurrency mining, with additional credential theft, lateral movement, and remote-access capabilities.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
18 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
3 malware families attributed to this actor across reporting.
4 CVEs this actor has used in observed campaigns. 4 of them exploited in the wild.
This is potentially intended to find machines vulnerable to MS17-010, given the actor's history of using EternalBlue.
We first observed this actor in July of 2018 exploiting a WebLogic vulnerability (CVE-2017-10271) to drop a miner that was associated with a campaign called "MassMiner".
Panda used massscan to look for a variety of different vulnerable servers and then exploited several different vulnerabilities, including the aforementioned Oracle bug and a remote code execution vulnerability in Apache Struts 2 (CVE-2017-5638).
In June, Panda began targeting a newer WebLogic vulnerability, CVE-2019-2725, but their TTPs remained the same.
84 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced as a previously observed APT campaign targeting Vietnam whose code base appears similar to the malware analyzed in this sample.
Conducting widespread illicit cryptocurrency mining campaigns, exploiting internet-facing vulnerabilities, deploying Monero miners and Gh0st RAT, and using lateral movement tooling including SMB scanning, brute forcing, and credential theft.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.