Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors ShaggyPanther

Also known as: LummaC2 Stealer, APT28, Pawn Storm, Fancy Bear, Sednit, services, public key cryptography, one private, the file association, handler, Netshell, header, magic bytes, the IconEnvironmentDataBlock, metamorphic, mutating code

Description

ShaggyPanther is a threat actor that primarily targets government entities in Taiwan and Malaysia. They have been active since 2008 and utilize hidden encrypted payloads in registry keys. Their activities have been detected in various locations, including Indonesia and Syria.

Goals & Targeting

Targeted Sectors

Media
Defense
Government
Financial services
Think tank
Transportation
Information technology

Targeted Countries / Regions

TW
KP
CN

AI Analysis

· 1 week ago

Executive Summary

ShaggyPanther is a persistent threat actor targeting government entities primarily in Taiwan and Malaysia since 2008. Their operations involve sophisticated techniques such as hiding encrypted payloads in registry keys, indicating a level of technical expertise aimed at maintaining long-term access and persistence.

Goals & Targeting

ShaggyPanther's strategic objectives appear to revolve around gaining unauthorized access to sensitive data within governmental organizations. Their targeting of specific sectors suggests a focus on espionage or information theft, particularly in regions with significant geopolitical interest. The actor likely seeks to achieve persistence and long-term access to their targets, enabling sustained operations and the ability to exfiltrate data over time.

Enhanced Description

ShaggyPanther is a cyber threat actor known for targeting government sectors in multiple regions, including Taiwan and Malaysia, with detections also reported in Indonesia and Syria. The actor's primary method involves embedding encrypted payloads within system registry keys, a technique that suggests a level of technical proficiency aimed at maintaining stealth and persistence within targeted networks. This approach allows ShaggyPanther to operate discreetly over extended periods, potentially exfiltrating sensitive information or conducting espionage activities. The actor's operations demonstrate strategic targeting with a focus on government entities, possibly indicating motivations tied to geopolitical interests or intelligence gathering.

Key Capabilities

  • Windows registry manipulation
  • Encrypted payload delivery
  • Persistent system access
  • Stealthy C2 communication

MITRE ATT&CK Tactics

Espionage
Initial Access
Persistence

Software / Tooling

Custom malware (encrypted payloads)
Registry-based persistence

Campaigns & Victims

ShaggyPanther's campaigns have demonstrated a long-term operational footprint, with activity tracing back to at least 2008. The actor has shown adaptability by targeting diverse geographic regions and maintaining low-profile operations through registry-based techniques. Notable past operations include detections in Taiwan, Malaysia, Indonesia, and Syria, indicating a broad operational reach with potential ties to state-sponsored activities or organized espionage groups.

IOC Patterns

  • Registry key modifications indicative of hidden payloads
  • Encrypted files associated with malicious activity
  • Unusual network traffic patterns linked to command and control

Recommended Actions

  • Implement enhanced monitoring for Windows Registry changes using SIEM tools
  • Conduct regular vulnerability assessments on governmental IT systems
  • Deploy endpoint detection and response (EDR) solutions to identify registry-based anomalies
  • Monitor network traffic for signs of encrypted or unusual data transfers

Suggested Tags

APT
Government-targeted
Registry-based attacks
Encryption

Confidence Assessment

Confidence in the data is moderate, as specific details about the actor's exact tools and motivations remain unclear. The primary information gap lies in the lack of detailed TTPs and associated software tools used by ShaggyPanther.

ATT&CK Techniques

Exfiltration
1 technique
Initial Access
1 technique
Privilege Escalation
1 technique
Reconnaissance
1 technique

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

References

  1. attack.mitre.org — Cited by web research for: services
  2. attack.mitre.org — Cited by web research for: PowerShell
  3. redcanary.com — Cited by web research for: SocGholish
  4. apt.etda.or.th — Cited by web research for: web shell

Intel Summary

40

Techniques

40

Tools

0

Campaigns

30

IOCs

0

Observed Data

13

Tactics

Tags

Government Targeting
APT
Government-targeted
Registry-based attacks
Encryption

Details

Type
Unknown
Primary Motivation
Financial gain
Country of Origin
C
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.