Goblin Panda, also known as Parched Taurus, is a China-aligned espionage threat actor associated with long-term intrusions against government targets in Southeast Asia. The group has been linked to operations conducted in support of Chinese state interests and is known for maintaining durable access in victim environments rather than pursuing disruptive or ransomware objectives. Observed tradecraft includes exploitation of Microsoft Exchange Server vulnerabilities for initial access, followed by deployment of web shells such as China Chopper to enable interactive command execution and persistence on internet-facing systems. Post-compromise activity has included reconnaissance, creation of attacker-controlled administrative accounts, credential access, and lateral movement toward high-value internal systems including web servers and domain controllers. Goblin Panda has used a broad toolset spanning custom and commodity malware, credential theft utilities, tunneling tools, and remote administration software. Reported capabilities include use of undocumented .NET backdoors, credential dumping with tools such as Mimikatz and LaZagne, Kerberos account enumeration and brute forcing, NTLM hash extraction techniques, LSASS dumping, and use of VPN and tunneling software to preserve access and move traffic covertly. Additional tooling associated with the activity includes Cobalt Strike, Quasar RAT, HTran, PuTTY/Plink, customized HDoor, Gh0st RAT-derived malware, and a Winnti-family variant. The actor has also been associated with scanner usage and extensive post-exploitation operations designed to expand and retain access over extended periods. The group’s operational profile is consistent with cyber espionage: stealthy persistence, credential theft, internal reconnaissance, and lateral movement in government environments. No high-confidence evidence indicates ransomware deployment as part of the referenced activity.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Attributed origin per open-source reporting.
1 malware family attributed to this actor across reporting.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.