Anchor Panda is a suspected China-linked advanced persistent threat designation referenced in connection with exploit development and tooling overlap involving Microsoft Office EPS exploitation. It has been associated with use of encrypted payload markers such as "PdPD," a trait also observed across other China-linked intrusion sets including Samurai Panda and Temper Panda, indicating shared development practices, code lineage, or exploit-builder reuse rather than a fully distinct public campaign profile. Publicly available reporting in this context does not provide a comprehensive standalone operational history for Anchor Panda, but it places the group within a cluster of espionage-oriented actors using weaponized Office documents for initial access in targeted intrusions across Asia. High-confidence details on Anchor Panda’s specific victimology, malware families, infrastructure, and full intrusion lifecycle are limited in the supplied facts.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.