Panda Burning Incense (熊猫烧香) is a Windows computer virus that spread rapidly across China from November 2006 to March 2007. The provided content states it was designed primarily to steal usernames and passwords. It is described as an infamous virus and as China’s first case involving the development and dissemination of a computer virus. The malware is directly associated with developer Li Jun, who was arrested and sentenced to prison in September 2007 in connection with the case. The content also notes that Jiang Jintao received a copy of the virus code from Li Jun through a QQ chat group, although Jiang reportedly did not further spread it and avoided arrest. High-confidence details in the content are limited to its Windows targeting, credential-theft purpose, rapid spread in China during late 2006 to early 2007, and its legal significance in China.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 distinct techniques documented for this family, organized by ATT&CK tactic.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A computer virus that attacked the Windows operating system. The article notes Jiang received a copy of its code from developer Li Jun, and that Li Jun was later arrested and jailed for developing and disseminating it.
Credential-stealing virus that modified system files and altered file icons; caused widespread infections in China (2006–2007).
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.