admin@338
Also reported as Team338, TEMPER PANDA, Admin338, MAGNESIUM, Temper Panda and 1 other name. Linked to China by three sources.
Reports per quarter
Techniques in ATT&CK
Listed by ATT&CK
No report from the last two years names a technique ID.
CVEs named in reports
- CVE-2009-4324 KEV
- CVE-2010-3333 KEV
- CVE-2011-3544 KEV
- CVE-2012-0158 KEV ransomware
- CVE-2012-4792 KEV
- CVE-2013-0422 KEV ransomware
- CVE-2014-0160 KEV
- CVE-2014-0322 KEV
- CVE-2014-1761 KEV
- CVE-2014-1776 KEV
- CVE-2014-4113 KEV
- CVE-2014-4114 KEV
Show all 44 CVEs Show fewer
- CVE-2014-6271 KEV
- CVE-2014-6277
- CVE-2014-6278 KEV
- CVE-2014-6352 KEV
- CVE-2014-7169 KEV
- CVE-2014-7186
- CVE-2014-7187
- CVE-2015-1701 KEV ransomware
- CVE-2015-2545 KEV
- CVE-2017-0213 KEV ransomware
- CVE-2017-11882 KEV ransomware
- CVE-2017-6327 KEV
- CVE-2017-6328
- CVE-2017-8759 KEV
- CVE-2018-0798 KEV
- CVE-2018-0802 KEV ransomware
- CVE-2018-20250 KEV ransomware
- CVE-2019-0708 KEV ransomware
- CVE-2019-0803 KEV ransomware
- CVE-2019-16920 KEV
- CVE-2019-19781 KEV ransomware
- CVE-2019-3396 KEV ransomware
- CVE-2020-0601 KEV
- CVE-2020-0688 KEV ransomware
- CVE-2020-10189 KEV
- CVE-2020-1040 KEV
- CVE-2020-1350 KEV
- CVE-2020-1472 KEV ransomware
- CVE-2020-5902 KEV ransomware
- CVE-2020-6789
- CVE-2020-8515 KEV
- CVE-2021-1732 KEV ransomware
KEV marks a CVE in CISA's Known Exploited Vulnerabilities Catalog, and “ransomware” marks one that the catalog records as used in ransomware campaigns.
Reports
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Poison Ivy (Malware Family)
Show all 45 reports Show fewer
-
BSides IR in Heterogeneous Environment
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor BSides IR in Heterogeneous Environment
-
CVE-2015-2545: overview of current threats - Securelist
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor CVE-2015-2545: overview of current threats - Securelist
-
CVE-2015-2545: overview of current threats
The link to Mirror on Box failed its last check. Mirror on Box Detailsfor CVE-2015-2545: overview of current threats
-
CVE-2015-2545- overview of current threats
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor CVE-2015-2545- overview of current threats
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor China-based Cyber Threat Group Uses Dropbox for Malware Communications and Targets Hong Kong Media Outlets
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor China-based Cyber Threat Group Uses Dropbox for Malware Communications and Targets Hong Kong Media Outlets « Threat Research | FireEye Inc
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Global Threat Intel Report
-
Poison Ivy Malware Analysis | FireEye
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Poison Ivy Malware Analysis | FireEye
-
Poison Ivy: Assessing Damage And Extracting Intelligence
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Poison Ivy: Assessing Damage And Extracting Intelligence
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Spear Phishing the News Cycle- APT Actors Leverage Interest in the Disappearance of Malaysian Flight MH 370
-
CrowdCasts Monthly: You Have an Adversary Problem
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor CrowdCasts Monthly: You Have an Adversary Problem
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor PIVY-Appendix
Newest first. Details opens the report in Explore.