All actors

TA428

Also reported as Vicious Panda, SixLittleMonkeys, Colourful Panda, BRONZE DUDLEY, Panda and 3 other names. Linked to China by three sources.

Reports
144
Last reported
Known CVEs
122
Origin
China
ID
ta428
Merge evidence
9 alias matches

Reports per quarter

  1. 2014 Q3: 1 report
  2. 2014 Q4: no reports
  3. 2015 Q1: no reports
  4. 2015 Q2: no reports
  5. 2015 Q3: no reports
  6. 2015 Q4: no reports
  7. 2016 Q1: no reports
  8. 2016 Q2: 1 report
  9. 2016 Q3: no reports
  10. 2016 Q4: 1 report
  11. 2017 Q1: no reports
  12. 2017 Q2: no reports
  13. 2017 Q3: 2 reports
  14. 2017 Q4: no reports
  15. 2018 Q1: no reports
  16. 2018 Q2: 1 report
  17. 2018 Q3: 2 reports
  18. 2018 Q4: 1 report
  19. 2019 Q1: 2 reports
  20. 2019 Q2: 1 report
  21. 2019 Q3: 5 reports
  22. 2019 Q4: 3 reports
  23. 2020 Q1: 13 reports
  24. 2020 Q2: 13 reports
  25. 2020 Q3: 11 reports
  26. 2020 Q4: 10 reports
  27. 2021 Q1: 17 reports
  28. 2021 Q2: 8 reports
  29. 2021 Q3: 4 reports
  30. 2021 Q4: 5 reports
  31. 2022 Q1: 6 reports
  32. 2022 Q2: 7 reports
  33. 2022 Q3: 8 reports
  34. 2022 Q4: 1 report
  35. 2023 Q1: 2 reports
  36. 2023 Q2: 2 reports
  37. 2023 Q3: no reports
  38. 2023 Q4: 2 reports
  39. 2024 Q1: no reports
  40. 2024 Q2: 1 report
  41. 2024 Q3: no reports
  42. 2024 Q4: no reports
  43. 2025 Q1: no reports
  44. 2025 Q2: 1 report
  45. 2025 Q3: 1 report
  46. 2025 Q4: 1 report
  47. 2026 Q1: no reports
  48. 2026 Q2: 11 reports
Dated reports, 2014 Q3 to 2026 Q2.

Techniques seen in the last two years

Show all 74 techniques Show fewer

Counts come from technique IDs in the actor's report text.

CVEs named in reports

Show all 122 CVEs Show fewer

KEV marks a CVE in CISA's Known Exploited Vulnerabilities Catalog, and “ransomware” marks one that the catalog records as used in ransomware campaigns.

Reports

  1. Emissary Panda, APT 27, LuckyMouse, Bronze Union

    date ORKL added it fromORKL

  2. Poison Ivy (Malware Family)

    date ORKL added it fromORKL

  3. Threat Group Cards: A Threat Actor Encyclopedia

    date ORKL added it fromORKL

  4. HyperBro (Malware Family)

    date ORKL added it fromORKL

  5. MimiKatz (Malware Family)

    date ORKL added it fromORKL

  6. PlugX (Malware Family)

    date ORKL added it fromORKL

Show all 144 reports Show fewer
  1. Emissary Panda, APT 27, LuckyMouse, Bronze Union

    date ORKL added it fromORKL

  2. Modern Asia APT groups TTPs

    file creation date Kaspersky fromORKL

  3. Worok- The big picture

    date in the title fromORKL

  4. APT trends report Q2 2020

    date in the title fromORKL

  5. Study of targeted attacks on Russian research institutes

    date in the title fromORKL

  6. eset_threat_report_t32021

    file creation date fromORKL

  7. MoonBounce_ the dark side of UEFI firmware _ Securelist

    date in the CCS '25 data Kaspersky fromORKLCCS '25 data

  8. MoonBounce- the dark side of UEFI firmware

    date in the title fromORKL

  9. APT trends report Q3 2021

    date in the title fromORKL

  10. The Art of Cyberwarfare Chinese APTs attack Russia

    date in the title fromORKL

  11. The Art of Cyberwarfare

    date in the CCS '25 data Solar JSOC fromORKLCCS '25 data

  12. eset_threat_report_t12021

    file creation date fromORKL

  13. Exchange servers under siege from at least 10 APT groups

    date in the title fromORKL

  14. Microsoft Exchange Zero Days - Mitigations and Detections

    date in the title fromORKL

  15. nao-sec.org-Royal Road ReDive

    date in the CCS '25 data nao_sec fromORKLCCS '25 data

  16. Royal Road! Re-Dive

    date in the title fromORKL

  17. Operation StealthyTrident- corporate software under attack

    date in the title fromORKL

  18. Panda’s New Arsenal- Part 1 Tmanger

    date in the title fromORKL

  19. IT threat evolution Q2 2020

    date in the title fromORKL

  20. APT_trends_report_Q2_2020_Securelist

    file creation date fromORKL

  21. ESET_Threat_Report_Q22020

    file creation date fromORKL

  22. APT trends report Q2 2020

    date in the title fromORKL

  23. Study of the APT attacks on state institutions in Kazakhstan and Kyrgyzstan

    Malpedia library date Doctor Web, Ltd. fromORKL

  24. cybersecurity-threatscape-2020-q1-eng

    file creation date fromORKL

  25. Microcin is here

    date in the title fromORKL

  26. McAfee Insights- Vicious Panda- The COVID Campaign

    date in the title fromORKL

  27. Vicious Panda_ The COVID Campaign - Check Point Research

    file creation date fromORKL

  28. APT36 jumps on the coronavirus bandwagon, delivers Crimson RAT _ Malwarebytes Labs

    date in the CCS '25 data Malwarebytes fromORKLCCS '25 data

  29. Vicious Panda- The COVID Campaign

    date in the title fromORKL

  30. An Overhead View of the Royal Road

    date in the title fromORKL

  31. TA428 Group abusing recent conflict between Iran and USA

    date in the title fromORKL

  32. Chinese_APT_Operation_LagTime_IT

    file creation date fromORKL

  33. Accenture Strategy Templates

    Malpedia library date fromORKL

  34. BSides IR in Heterogeneous Environment

    Malpedia library date fromORKL

Newest first. Details opens the report in Explore.