DAGGER PANDA
Also reported as RedFoxtrot, Moshen Dragon, Red Wendigo, IceFog, Trident and 9 other names. Linked to China by three sources.
Reports per quarter
Techniques seen in the last two years
- T1003.001 2 reports
- T1016 2 reports
- T1021.002 2 reports
- T1057 2 reports
- T1059.003 2 reports
- T1087.001 2 reports
- T1095 2 reports
- T1140 2 reports
- T1543.003 2 reports
- T1555.003 2 reports
Show all 63 techniques Show fewer
- T1003.002 1 report
- T1007 1 report
- T1008 1 report
- T1027.001 1 report
- T1027.002 1 report
- T1033 1 report
- T1036.004 1 report
- T1036.005 1 report
- T1040 1 report
- T1053.002 1 report
- T1053.005 1 report
- T1055 1 report
- T1055.001 1 report
- T1055.012 1 report
- T1056.001 1 report
- T1059.001 1 report
- T1059.005 1 report
- T1068 1 report
- T1069.002 1 report
- T1071 1 report
- T1071.001 1 report
- T1071.004 1 report
- T1072 1 report
- T1078.002 1 report
- T1082 1 report
- T1083 1 report
- T1087.002 1 report
- T1090.001 1 report
- T1105 1 report
- T1106 1 report
- T1112 1 report
- T1119 1 report
- T1132.001 1 report
- T1197 1 report
- T1218.011 1 report
- T1546.015 1 report
- T1547.001 1 report
- T1548.002 1 report
- T1553.002 1 report
- T1556.002 1 report
- T1560.001 1 report
- T1564.001 1 report
- T1566.001 1 report
- T1566.002 1 report
- T1569.002 1 report
- T1571 1 report
- T1572 1 report
- T1573.001 1 report
- T1574 1 report
- T1583.001 1 report
- T1583.004 1 report
- T1614.001 1 report
- T1620 1 report
Counts come from technique IDs in the actor's report text.
CVEs named in reports
- CVE-2008-3431 KEV
- CVE-2009-0927 KEV
- CVE-2009-3129 KEV
- CVE-2010-0188 KEV ransomware
- CVE-2010-0232 KEV
- CVE-2010-0249 KEV
- CVE-2010-0806 KEV
- CVE-2010-1297 KEV
- CVE-2010-2884
- CVE-2010-3333 KEV
- CVE-2010-4398 KEV
- CVE-2011-0609 KEV
Show all 178 CVEs Show fewer
- CVE-2011-0611 KEV
- CVE-2011-1255
- CVE-2011-2005 KEV
- CVE-2011-2110
- CVE-2011-3544 KEV
- CVE-2011-4369
- CVE-2012-0158 KEV ransomware
- CVE-2012-0422
- CVE-2012-0773
- CVE-2012-0779
- CVE-2012-1535 KEV
- CVE-2012-1723 KEV ransomware
- CVE-2012-1856 KEV
- CVE-2012-1875
- CVE-2012-1889 KEV
- CVE-2012-4681 KEV ransomware
- CVE-2012-4792 KEV
- CVE-2013-0422 KEV ransomware
- CVE-2013-0640 KEV
- CVE-2013-0808
- CVE-2013-1331 KEV
- CVE-2013-1347 KEV
- CVE-2013-1493
- CVE-2013-2729 KEV
- CVE-2013-3346 KEV
- CVE-2013-3660 KEV
- CVE-2013-3893 KEV
- CVE-2013-3897 KEV
- CVE-2013-3906 KEV
- CVE-2013-4979
- CVE-2013-5065 KEV
- CVE-2013-7331 KEV
- CVE-2014-0322 KEV
- CVE-2014-0497 KEV
- CVE-2014-0515
- CVE-2014-1761 KEV
- CVE-2014-1776 KEV
- CVE-2014-4076
- CVE-2014-4113 KEV
- CVE-2014-4114 KEV
- CVE-2014-6332 KEV
- CVE-2014-6352 KEV
- CVE-2014-8439 KEV
- CVE-2015-1641 KEV
- CVE-2015-1642 KEV
- CVE-2015-1701 KEV ransomware
- CVE-2015-2387 KEV
- CVE-2015-2419 KEV
- CVE-2015-2424 KEV
- CVE-2015-2545 KEV
- CVE-2015-2546 KEV ransomware
- CVE-2015-2590 KEV
- CVE-2015-3043 KEV
- CVE-2015-3105
- CVE-2015-4902 KEV
- CVE-2015-5119 KEV
- CVE-2015-5122 KEV
- CVE-2015-7645 KEV ransomware
- CVE-2015-8651 KEV
- CVE-2016-0034 KEV ransomware
- CVE-2016-0147
- CVE-2016-0167 KEV ransomware
- CVE-2016-0189 KEV ransomware
- CVE-2016-0984 KEV
- CVE-2016-1010 KEV
- CVE-2016-1019 KEV ransomware
- CVE-2016-4117 KEV ransomware
- CVE-2016-4119
- CVE-2016-4171 KEV
- CVE-2016-5195 KEV
- CVE-2016-7255 KEV ransomware
- CVE-2016-7855 KEV
- CVE-2017-0143 KEV ransomware
- CVE-2017-0144 KEV ransomware
- CVE-2017-0146 KEV ransomware
- CVE-2017-0147 KEV ransomware
- CVE-2017-0199 KEV ransomware
- CVE-2017-0213 KEV ransomware
- CVE-2017-0261 KEV
- CVE-2017-0262 KEV
- CVE-2017-0263 KEV
- CVE-2017-10271 KEV ransomware
- CVE-2017-11317 KEV
- CVE-2017-11357 KEV ransomware
- CVE-2017-1182
- CVE-2017-11882 KEV ransomware
- CVE-2017-12824
- CVE-2017-15399
- CVE-2017-1882
- CVE-2017-7269 KEV
- CVE-2017-8291 KEV
- CVE-2017-8570 KEV
- CVE-2017-8759 KEV
- CVE-2017-9248 KEV
- CVE-2018-0798 KEV
- CVE-2018-0802 KEV ransomware
- CVE-2018-0824 KEV
- CVE-2018-13379 KEV ransomware
- CVE-2018-20250 KEV ransomware
- CVE-2018-4878 KEV ransomware
- CVE-2018-8174 KEV ransomware
- CVE-2018-8453 KEV ransomware
- CVE-2018-8570
- CVE-2018-8611 KEV
- CVE-2018-8872
- CVE-2019-0604 KEV ransomware
- CVE-2019-0797 KEV
- CVE-2019-10149 KEV
- CVE-2019-11510 KEV ransomware
- CVE-2019-16098
- CVE-2019-1653 KEV
- CVE-2019-17026 KEV
- CVE-2019-18935 KEV ransomware
- CVE-2019-19781 KEV ransomware
- CVE-2019-2215 KEV
- CVE-2019-2725 KEV ransomware
- CVE-2019-7609 KEV
- CVE-2019-9489
- CVE-2019-9670 KEV
- CVE-2020-0674 KEV
- CVE-2020-0688 KEV ransomware
- CVE-2020-0796 KEV ransomware
- CVE-2020-0986 KEV
- CVE-2020-10189 KEV
- CVE-2020-1380 KEV
- CVE-2020-1472 KEV ransomware
- CVE-2020-14882 KEV
- CVE-2020-15782
- CVE-2020-1664
- CVE-2020-17144 KEV
- CVE-2020-2021 KEV ransomware
- CVE-2020-4006 KEV
- CVE-2020-5135 KEV ransomware
- CVE-2020-5902 KEV ransomware
- CVE-2020-8468 KEV
- CVE-2021-1675 KEV ransomware
- CVE-2021-21972 KEV ransomware
- CVE-2021-22555 KEV
- CVE-2021-26605
- CVE-2021-26855 KEV ransomware
- CVE-2021-26857 KEV ransomware
- CVE-2021-26858 KEV ransomware
- CVE-2021-27065 KEV ransomware
- CVE-2021-31207 KEV ransomware
- CVE-2021-34473 KEV ransomware
- CVE-2021-34481
- CVE-2021-34523 KEV ransomware
- CVE-2021-34527 KEV ransomware
- CVE-2021-36958
- CVE-2021-4034 KEV ransomware
- CVE-2021-44515 KEV
- CVE-2022-1040 KEV
- CVE-2022-24682 KEV ransomware
- CVE-2022-24934
- CVE-2022-27924 KEV ransomware
- CVE-2022-27925 KEV ransomware
- CVE-2022-30190 KEV ransomware
- CVE-2022-30333 KEV ransomware
- CVE-2022-37042 KEV ransomware
- CVE-2023-46747 KEV ransomware
- CVE-2024-1709 KEV ransomware
- CVE-2024-24919 KEV ransomware
- CVE-2024-8190 KEV
- CVE-2024-8963 KEV
- CVE-2025-55182 KEV ransomware
- CVE-2026-21236
KEV marks a CVE in CISA's Known Exploited Vulnerabilities Catalog, and “ransomware” marks one that the catalog records as used in ransomware campaigns.
Reports
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor ShadowPad (Malware Family)
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Poison Ivy (Malware Family)
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor PlugX (Malware Family)
-
Icefog, Dagger Panda - Threat Group Cards: A Threat Actor Encyclopedia
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Icefog, Dagger Panda - Threat Group Cards: A Threat Actor Encyclopedia
Show all 144 reports Show fewer
-
THALES%20THREAT%20HANDBOOK%202022%20Light%20Version_1.pdf
The original link failed its last check. Original publisher Detailsfor THALES%20THREAT%20HANDBOOK%202022%20Light%20Version_1.pdf
-
Space Pirates analyzing the tools and connections of a new hacker group
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Space Pirates analyzing the tools and connections of a new hacker group
-
Chinese Naikon Group Back with New Espionage Attack
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Chinese Naikon Group Back with New Espionage Attack
-
Moshen Dragon’s Triad-and-Error Approach - Abusing Security Software to Sideload PlugX and ShadowPad
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Moshen Dragon’s Triad-and-Error Approach - Abusing Security Software to Sideload PlugX and ShadowPad
-
Continued Targeting of Indian Power Grid Assets by Chinese State-Sponsored Activity Group
The link to Mirror on Box failed its last check. Mirror on Box Detailsfor Continued Targeting of Indian Power Grid Assets by Chinese State-Sponsored Activity Group
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor PlugX- A Talisman to Behold
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor ShadowPad Malware Analysis
-
ShadowPad Malware Analysis _ Secureworks
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor ShadowPad Malware Analysis _ Secureworks
-
Winnti is Coming - Evolution after Prosecution@HITCON2021
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Winnti is Coming - Evolution after Prosecution@HITCON2021
-
Winnti is Coming - Evolution after Prosecution
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Winnti is Coming - Evolution after Prosecution
-
4 Chinese APT Groups Identified Targeting Mail Server of Afghan Telecommunications Firm Roshan
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor 4 Chinese APT Groups Identified Targeting Mail Server of Afghan Telecommunications Firm Roshan
-
Wiper Malware Riding the 2021 Tokyo Olympic Games
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Wiper Malware Riding the 2021 Tokyo Olympic Games
-
The original link failed its last check. Original publisher Detailsfor Презентация PowerPoint
-
the-operations-of-winnti-group.pdf
The original link failed its last check. Original publisher Detailsfor the-operations-of-winnti-group.pdf
-
Higaisa or Winnti? APT41 backdoors, old and new
The original link failed its last check. Original publisher Detailsfor Higaisa or Winnti? APT41 backdoors, old and new
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor nao-sec.org-Royal Road ReDive
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Royal Road! Re-Dive
-
The original link failed its last check. Original publisher Detailsfor winnti-2020-rus.pdf
-
Attribution is in the object- using RTF object dimensions to track APT phishing weaponizers
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Attribution is in the object- using RTF object dimensions to track APT phishing weaponizers
-
An Overhead View of the Royal Road
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor An Overhead View of the Royal Road
-
Cyber Threat Landscape in Japan – Revealing Threat in the Shadow
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Cyber Threat Landscape in Japan – Revealing Threat in the Shadow
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor [CB19] Cyber Threat Landscape in Japan – Revealing Threat in the Shadow by Chi En Shen (Ashley) Oleg Bondarenko
-
Threat Group Cards: A Threat Actor Encyclopedia
The link to Mirror on Box failed its last check. Mirror on Box Detailsfor Threat Group Cards: A Threat Actor Encyclopedia
-
Threat Group Cards: A Threat Actor Encyclopedia
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Threat Group Cards: A Threat Actor Encyclopedia
-
Into the Fog - The Return of ICEFOG APT
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Into the Fog - The Return of ICEFOG APT
-
Into the Fog - The Return of ICEFOG APT
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Into the Fog - The Return of ICEFOG APT
-
The original link failed its last check. Original publisher Detailsfor Accenture Strategy Templates
-
Analyzing Digital Quartermasters in Asia – Do Chinese and Indian APTs Have a Shared Supply Chain?
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Analyzing Digital Quartermasters in Asia – Do Chinese and Indian APTs Have a Shared Supply Chain?
-
Goblin Panda changes the dropper and reuses the old infrastructure
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Goblin Panda changes the dropper and reuses the old infrastructure
-
%5bAnalysis%5dDefense_Industry_Threats.pdf
The original link failed its last check. Original publisher Detailsfor %5bAnalysis%5dDefense_Industry_Threats.pdf
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor 洋葱狗行动(Operation OnionDog)
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Operation OnionDog
-
Forced to Adapt: XSLCmd Backdoor Now on OS X | FireEye Blog
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Forced to Adapt: XSLCmd Backdoor Now on OS X | FireEye Blog
-
Unveiling Careto - The Masked Apt
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Unveiling Careto - The Masked Apt
-
securelist.com-The Icefog APT Hits US Targets With Java Backdoor
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor securelist.com-The Icefog APT Hits US Targets With Java Backdoor
-
The Icefog APT Hits US Targets With Java Backdoor
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor The Icefog APT Hits US Targets With Java Backdoor
-
CrowdCasts Monthly: You Have an Adversary Problem
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor CrowdCasts Monthly: You Have an Adversary Problem
-
The Icefog Apt: A Tale Of Cloak And Three Daggers
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor The Icefog Apt: A Tale Of Cloak And Three Daggers
-
The Icefog APT- A Tale of Cloak and Three Daggers
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor The Icefog APT- A Tale of Cloak and Three Daggers
Newest first. Details opens the report in Explore.