TA428
Also reported as Vicious Panda, SixLittleMonkeys, Colourful Panda, BRONZE DUDLEY, Panda and 3 other names. Linked to China by three sources.
Reports per quarter
Techniques seen in the last two years
- T1033 2 reports
- T1055 2 reports
- T1057 2 reports
- T1082 2 reports
- T1083 2 reports
- T1105 2 reports
- T1106 2 reports
- T1140 2 reports
- T1566.001 2 reports
- T1566.002 2 reports
Show all 74 techniques Show fewer
- T1003.001 1 report
- T1008 1 report
- T1010 1 report
- T1012 1 report
- T1016 1 report
- T1021.002 1 report
- T1027 1 report
- T1027.001 1 report
- T1027.002 1 report
- T1036 1 report
- T1036.004 1 report
- T1036.005 1 report
- T1040 1 report
- T1047 1 report
- T1053 1 report
- T1053.002 1 report
- T1053.005 1 report
- T1055.001 1 report
- T1056 1 report
- T1056.001 1 report
- T1059 1 report
- T1059.003 1 report
- T1059.005 1 report
- T1068 1 report
- T1069.002 1 report
- T1071.001 1 report
- T1071.004 1 report
- T1078 1 report
- T1078.002 1 report
- T1087 1 report
- T1087.001 1 report
- T1087.002 1 report
- T1090.001 1 report
- T1091 1 report
- T1095 1 report
- T1112 1 report
- T1119 1 report
- T1124 1 report
- T1132.001 1 report
- T1134 1 report
- T1190 1 report
- T1195 1 report
- T1197 1 report
- T1218.011 1 report
- T1497 1 report
- T1543.003 1 report
- T1546.015 1 report
- T1547.001 1 report
- T1548.002 1 report
- T1553.002 1 report
- T1555.003 1 report
- T1557 1 report
- T1560 1 report
- T1560.001 1 report
- T1564.001 1 report
- T1566.003 1 report
- T1569.002 1 report
- T1571 1 report
- T1572 1 report
- T1573.001 1 report
- T1614 1 report
- T1614.001 1 report
- T1620 1 report
- T1659 1 report
Counts come from technique IDs in the actor's report text.
CVEs named in reports
- CVE-2008-3431 KEV
- CVE-2012-0158 KEV ransomware
- CVE-2012-5687
- CVE-2013-5947
- CVE-2013-7389
- CVE-2014-1225
- CVE-2014-1761 KEV
- CVE-2014-2962
- CVE-2014-4019
- CVE-2014-4114 KEV
- CVE-2014-4404 KEV
- CVE-2014-6352 KEV
Show all 122 CVEs Show fewer
- CVE-2014-8361 KEV
- CVE-2014-9583
- CVE-2015-0554
- CVE-2015-1130 KEV
- CVE-2015-1635 KEV
- CVE-2015-2051 KEV
- CVE-2015-2545 KEV
- CVE-2015-7248
- CVE-2015-7254
- CVE-2015-7645 KEV ransomware
- CVE-2016-1019 KEV ransomware
- CVE-2016-4117 KEV ransomware
- CVE-2017-0144 KEV ransomware
- CVE-2017-0199 KEV ransomware
- CVE-2017-0213 KEV ransomware
- CVE-2017-0261 KEV
- CVE-2017-0262 KEV
- CVE-2017-0263 KEV
- CVE-2017-11882 KEV ransomware
- CVE-2017-18368 KEV
- CVE-2017-5638 KEV ransomware
- CVE-2017-6327 KEV
- CVE-2017-6328
- CVE-2017-8570 KEV
- CVE-2017-8759 KEV
- CVE-2018-0798 KEV
- CVE-2018-0802 KEV ransomware
- CVE-2018-10562 KEV ransomware
- CVE-2018-11776 KEV
- CVE-2018-13379 KEV ransomware
- CVE-2018-13382 KEV ransomware
- CVE-2018-13383 KEV ransomware
- CVE-2018-1579
- CVE-2018-20250 KEV ransomware
- CVE-2018-8174 KEV ransomware
- CVE-2018-8570
- CVE-2018-8641
- CVE-2018-8653 KEV
- CVE-2019-0604 KEV ransomware
- CVE-2019-0708 KEV ransomware
- CVE-2019-0803 KEV ransomware
- CVE-2019-10149 KEV
- CVE-2019-11510 KEV ransomware
- CVE-2019-11539 KEV ransomware
- CVE-2019-1367 KEV ransomware
- CVE-2019-1429 KEV
- CVE-2019-16759 KEV
- CVE-2019-16920 KEV
- CVE-2019-19781 KEV ransomware
- CVE-2019-2215 KEV
- CVE-2019-3396 KEV ransomware
- CVE-2020-0601 KEV
- CVE-2020-0674 KEV
- CVE-2020-0688 KEV ransomware
- CVE-2020-0796 KEV ransomware
- CVE-2020-10189 KEV
- CVE-2020-1040 KEV
- CVE-2020-1350 KEV
- CVE-2020-1472 KEV ransomware
- CVE-2020-1664
- CVE-2020-17530 KEV
- CVE-2020-2551 KEV
- CVE-2020-5135 KEV ransomware
- CVE-2020-5902 KEV ransomware
- CVE-2020-6789
- CVE-2020-7961 KEV
- CVE-2020-8515 KEV
- CVE-2021-21551 KEV
- CVE-2021-21972 KEV ransomware
- CVE-2021-24085
- CVE-2021-25323
- CVE-2021-25324
- CVE-2021-25325
- CVE-2021-26084 KEV ransomware
- CVE-2021-26605
- CVE-2021-26855 KEV ransomware
- CVE-2021-26857 KEV ransomware
- CVE-2021-26858 KEV ransomware
- CVE-2021-27065 KEV ransomware
- CVE-2021-30657 KEV
- CVE-2021-31195
- CVE-2021-31196 KEV
- CVE-2021-31207 KEV ransomware
- CVE-2021-31805
- CVE-2021-33766 KEV
- CVE-2021-34473 KEV ransomware
- CVE-2021-34523 KEV ransomware
- CVE-2021-35394 KEV
- CVE-2021-36934 KEV
- CVE-2021-38647 KEV ransomware
- CVE-2021-42321 KEV ransomware
- CVE-2021-44228 KEV ransomware
- CVE-2021-44832
- CVE-2021-45105
- CVE-2022-1040 KEV
- CVE-2022-22963 KEV
- CVE-2022-22965 KEV
- CVE-2022-26134 KEV ransomware
- CVE-2022-26138 KEV
- CVE-2022-26352 KEV ransomware
- CVE-2022-30190 KEV ransomware
- CVE-2022-34305
- CVE-2022-41040 KEV ransomware
- CVE-2022-41082 KEV ransomware
- CVE-2022-42475 KEV ransomware
- CVE-2022-47966 KEV ransomware
- CVE-2023-36884 KEV ransomware
- CVE-2024-11182 KEV
- CVE-2024-49039 KEV ransomware
- CVE-2024-9680 KEV ransomware
KEV marks a CVE in CISA's Known Exploited Vulnerabilities Catalog, and “ransomware” marks one that the catalog records as used in ransomware campaigns.
Reports
-
Emissary Panda, APT 27, LuckyMouse, Bronze Union
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Emissary Panda, APT 27, LuckyMouse, Bronze Union
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Poison Ivy (Malware Family)
-
Threat Group Cards: A Threat Actor Encyclopedia
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Threat Group Cards: A Threat Actor Encyclopedia
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor HyperBro (Malware Family)
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor MimiKatz (Malware Family)
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor PlugX (Malware Family)
Show all 144 reports Show fewer
-
Emissary Panda, APT 27, LuckyMouse, Bronze Union
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Emissary Panda, APT 27, LuckyMouse, Bronze Union
-
The link to Mirror on Box failed its last check. Mirror on Box Detailsfor Modern Asia APT groups TTPs
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Worok- The big picture
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor APT trends report Q2 2020
-
Space Pirates analyzing the tools and connections of a new hacker group
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Space Pirates analyzing the tools and connections of a new hacker group
-
PortDoor- New Chinese APT Backdoor Attack Targets Russian Defense Sector
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor PortDoor- New Chinese APT Backdoor Attack Targets Russian Defense Sector
-
Study of targeted attacks on Russian research institutes
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Study of targeted attacks on Russian research institutes
-
The APT Fallout of Vulnerabilities such as ProxyLogon, OGNL Injection, and log4shell
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor The APT Fallout of Vulnerabilities such as ProxyLogon, OGNL Injection, and log4shell
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor eset_threat_report_t32021
-
MoonBounce_ the dark side of UEFI firmware _ Securelist
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor MoonBounce_ the dark side of UEFI firmware _ Securelist
-
MoonBounce- the dark side of UEFI firmware
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor MoonBounce- the dark side of UEFI firmware
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor APT trends report Q3 2021
-
The Art of Cyberwarfare Chinese APTs attack Russia
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor The Art of Cyberwarfare Chinese APTs attack Russia
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor The Art of Cyberwarfare
-
ThunderCats Hack the FSB - Your Taxes Didn’t Pay For This Op
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor ThunderCats Hack the FSB - Your Taxes Didn’t Pay For This Op
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor eset_threat_report_t12021
-
PortDoor: New Chinese APT Backdoor Attack Targets Russian Defense Sector
The link to Mirror on Box failed its last check. Mirror on Box Detailsfor PortDoor: New Chinese APT Backdoor Attack Targets Russian Defense Sector
-
China-linked TA428 Continues to Target Russia and Mongolia IT Companies
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor China-linked TA428 Continues to Target Russia and Mongolia IT Companies
-
Examining Exchange Exploitation and its Lessons for Defenders
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Examining Exchange Exploitation and its Lessons for Defenders
-
Exchange servers under siege from at least 10 APT groups
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Exchange servers under siege from at least 10 APT groups
-
Microsoft Exchange Zero Days - Mitigations and Detections
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Microsoft Exchange Zero Days - Mitigations and Detections
-
nccTrojan used in targeted attack by TA428 group against defense and aviation organizations
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor nccTrojan used in targeted attack by TA428 group against defense and aviation organizations
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor VinCSS Blog_ [RE020] ElephantRAT (Kunming version)_ our latest discovered RAT of Panda and the similarities with recently Smanager RAT
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor nao-sec.org-Royal Road ReDive
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Royal Road! Re-Dive
-
Operation StealthyTrident- corporate software under attack
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Operation StealthyTrident- corporate software under attack
-
Panda’s New Arsenal- Part 1 Tmanger
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Panda’s New Arsenal- Part 1 Tmanger
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor IT threat evolution Q2 2020
-
APT_trends_report_Q2_2020_Securelist
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor APT_trends_report_Q2_2020_Securelist
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor ESET_Threat_Report_Q22020
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor APT trends report Q2 2020
-
Study of the APT attacks on state institutions in Kazakhstan and Kyrgyzstan
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Study of the APT attacks on state institutions in Kazakhstan and Kyrgyzstan
-
cybersecurity-threatscape-2020-q1-eng
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor cybersecurity-threatscape-2020-q1-eng
-
Microcin is here With asynchronous sockets, steganography, GitLab ban and a sock
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Microcin is here With asynchronous sockets, steganography, GitLab ban and a sock
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Microcin is here
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor COVID-19 and New Year greetings- an investigation into the tools and methods used by the Higaisa group
-
Mikroceen_ Spying backdoor leveraged in high‑profile networks in Central Asia _ WeLiveSecurity
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Mikroceen_ Spying backdoor leveraged in high‑profile networks in Central Asia _ WeLiveSecurity
-
APT Group Planted Backdoors Targeting High Profile Networks in Central Asia
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor APT Group Planted Backdoors Targeting High Profile Networks in Central Asia
-
APT Group Planted Backdoors Targeting High Profile Networks in Central Asia - Avast Threat Labs
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor APT Group Planted Backdoors Targeting High Profile Networks in Central Asia - Avast Threat Labs
-
Mikroceen- Spying backdoor leveraged in high‑profile networks in Central Asia
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Mikroceen- Spying backdoor leveraged in high‑profile networks in Central Asia
-
McAfee Insights- Vicious Panda- The COVID Campaign
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor McAfee Insights- Vicious Panda- The COVID Campaign
-
Vicious Panda_ The COVID Campaign - Check Point Research
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Vicious Panda_ The COVID Campaign - Check Point Research
-
APT36 jumps on the coronavirus bandwagon, delivers Crimson RAT _ Malwarebytes Labs
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor APT36 jumps on the coronavirus bandwagon, delivers Crimson RAT _ Malwarebytes Labs
-
Vicious Panda- The COVID Campaign
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Vicious Panda- The COVID Campaign
-
An Overhead View of the Royal Road
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor An Overhead View of the Royal Road
-
TA428 Group abusing recent conflict between Iran and USA
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor TA428 Group abusing recent conflict between Iran and USA
-
Chinese_APT_Operation_LagTime_IT
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Chinese_APT_Operation_LagTime_IT
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Chinese APT “Operation LagTime IT” Targets Government Information Technology Agencies in Eastern Asia
-
The original link failed its last check. Original publisher Detailsfor Accenture Strategy Templates
-
BSides IR in Heterogeneous Environment
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor BSides IR in Heterogeneous Environment
Newest first. Details opens the report in Explore.