Temper Panda is a China-linked advanced persistent threat designation associated with targeted intrusion activity and infrastructure overlap observed in broader East and South Asian espionage operations. The group is also known as admin@338. It has been linked to command-and-control infrastructure seen in other APT incidents and is one of several China-nexus clusters associated with use of exploit tooling built around Microsoft Office EPS parsing vulnerabilities. Temper Panda has been associated with targeted attacks delivered through spear-phishing documents exploiting client-side vulnerabilities for initial access. Reporting also links the group to exploit variants marked by the "PdPD" payload convention, a trait shared across multiple Chinese intrusion sets, indicating either tooling reuse, shared development lineage, or operational overlap. The broader activity pattern tied to this ecosystem includes malicious document delivery, execution of embedded shellcode, deployment of backdoors and loaders, and follow-on remote access capabilities such as system profiling, file manipulation, process and service control, command execution, and data transfer. The actor is generally assessed as espionage-motivated and aligned with Chinese state interests. Public aliasing places Temper Panda within the wider landscape of Chinese APT tracking names that include overlapping clusters and partially related operators rather than a universally standardized single identity.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Attributed origin per open-source reporting.
2 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.