Genesis Panda is a China-linked threat actor active since at least January 2024 and associated with high-volume cloud-focused intrusion activity. The group has targeted organizations across multiple countries, with reported victim sectors including financial services, media, telecommunications, and technology. Its operations are consistent with cyber espionage and may also overlap with initial-access-broker behavior, as reporting notes broad exploitation of exposed web-facing vulnerabilities combined with comparatively limited exfiltration in some cases. Genesis Panda is notable for manipulating cloud services as part of hands-on-keyboard intrusions. The actor has used cloud infrastructure to support tool deployment, command-and-control communications, and data exfiltration, while also targeting cloud service provider accounts to expand access and establish fallback persistence. A recurring tradecraft element is querying cloud Instance Metadata Service interfaces on compromised cloud-hosted systems to obtain control-plane credentials and enumerate cloud configurations. The group then uses credentials obtained from compromised virtual machines to move deeper within victim cloud accounts, maintain persistence, and evade detection by abusing trusted access and cloud-native mechanisms. The actor has also been observed moving rapidly after public vulnerability disclosure, with attacks launched within 24 hours in some cases. Reported behavior includes exploitation of numerous web-facing vulnerabilities, compromise of cloud-hosted systems, credential theft from cloud environments, persistence through cloud account abuse, and limited but deliberate exfiltration. Genesis Panda is widely tracked as a China-nexus intrusion set focused on cloud-centric access expansion, persistence, and intelligence collection.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Attributed origin per open-source reporting.
4 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
China-linked threat actor cited as rapidly exploiting newly disclosed vulnerabilities within 24 hours of disclosure.
China-linked cloud intrusion activity abusing cloud misconfigurations and trusted access to evade detection.
China-linked high-volume operations (active since at least Jan 2024) focused on compromising cloud-hosted systems and CSP accounts to enable future intelligence collection; likely leverages broad web-facing vulnerability exploitation with limited exfiltration, potentially acting as an initial access broker.
Genesis Panda is a China-linked group specializing in cloud intrusions, deploying tools, establishing C2, exfiltrating data, and maintaining persistence by attacking CSP accounts and leveraging cloud VM credentials.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.