Cisco Talos documented a long-running cryptomining campaign by an actor it tracks as Panda, which used public remote-code-execution flaws to compromise internet-facing servers and deploy Monero miners. The activity spanned 2018 through August 2019 and abused multiple vulnerabilities, including Oracle WebLogic CVE-2019-2725 and CVE-2017-10271, Apache Struts 2 CVE-2017-5638, and ThinkPHP CNVD-2018-24942. Oracle separately issued a security alert for CVE-2019-2725, one of the flaws later incorporated into Panda's intrusion chain.
Talos said the actor frequently rotated infrastructure across domains including idc3389[.]top, bulehero[.]in, hognoob[.]se, and fxxxxxxk[.]me, while keeping consistent tactics such as PowerShell- and Certutil-based payload delivery, SMB scanning, brute forcing, and lateral movement with Shadow Brokers-linked exploits and Mimikatz. In some cases Panda also deployed Gh0st RAT and used Chinese-language IP geolocation services during victim profiling. Organizations in banking, healthcare, transportation, telecommunications, and IT services were affected, and Talos estimated the campaign generated about 1,215 XMR—roughly $100,000 at the time—showing that opportunistic cryptomining remained an active enterprise threat.

Get the actors, campaigns, and ATT&CK mapping behind it.
6 events from the most recent confirmed update back to the earliest known activity.
Talos published research describing Panda as a long-running and adaptable cryptomining threat tracked from 2018 through August 2019. The report said the actor exploited multiple public vulnerabilities, affected organizations across several sectors, and had earned roughly 1,215 XMR.
In March 2019, Panda moved campaign infrastructure to subdomains of hognoob[.]se while keeping similar tactics, techniques, and procedures. Talos observed payload delivery from fid[.]hognoob[.]se and retrieval of miner components and configuration data from related hosts.
In January 2019, Talos observed Panda exploiting ThinkPHP vulnerability CNVD-2018-24942 to download download.exe from a46[.]bulehero[.]in and upload the hydra.php web shell. The web shell enabled arbitrary system command execution via HTTP parameters.
By October 2018, Talos noted that the configuration file hosted on list[.]idc3389[.]top had reportedly been downloaded more than 300,000 times. This indicated substantial scale for the Panda mining operation.
Talos reported that the Panda threat actor began conducting widespread illicit cryptocurrency mining campaigns in July 2018. The activity was linked to the earlier MassMiner campaign through shared wallet usage, infrastructure, and post-exploitation PowerShell commands.
Oracle published a security alert for CVE-2019-2725. The reference establishes the vendor disclosure of the WebLogic vulnerability later cited by Talos as one of Panda's exploited flaws.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 84 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Get the adversaries, campaigns, and ATT&CK mapping behind this technique, with detections ready to deploy.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.