Also known as: UNC6384, CL-STA-0969, the LightBasin activity cluster
LIMINAL PANDA, also referred to as UNC6384, CL-STA-0969 or LightBasin, has been active since at least 2019 targeting telecommunications operators worldwide. The adversary exploits commonly‑used credentials such as "huawei" and gains SSH access to external DNS servers within GPRS networks, allowing lateral movement across partner infrastructures. Once inside, the actors deploy a suite of custom tools—including PingPong backdoor, TinyShell command‐and‐control binary, SIGTRANslator for signalling protocol manipulation, CordScan for network scanning, and the sgsnemu2 GSM‑SGSN emulator—to harvest subscriber information and call metadata. Their methodology relies on sophisticated operational security. They modify legitimate system binaries (e.g., an iptables wrapper) to obscure firewall rule changes, alter init scripts (/etc/rc.d/init.d/) for persistence, and schedule execution windows of 30 minutes between 02:15‑02:45 UTC to minimise detection. The actor also chains SOCKS5 proxies via ProxyChains, often hosted on commercial VPS providers such as Vultr, to pivot internally and disguise C2 traffic. In addition to custom tools, they abuse publicly available utilities (Nexus, PowerShell scripts) and exploit multiple CVEs—including CVE‑2016‑5195, CVE‑2021‑4034 and CVE‑2021‑3156—for initial access or privilege escalation. While primarily focused on telecommunications assets for signals intelligence, LIMINAL PANDA’s tactics exhibit a generalist approach that could extend to enterprises sharing vendor relationships with telecom operators. Their campaigns are characterised by stealth, persistence, and an emphasis on exfiltrating large volumes of network traffic rather than financial gain.
Targeted Sectors
Targeted Countries / Regions
Executive Summary
LIMINAL PANDA is a China‑linked APT that specialises in infiltrating global telecommunications networks for SIGINT collection. The group utilizes weak passwords, custom backdoors and telecom‑specific emulation tools to spread laterally and exfiltrate subscriber data while remaining under the radar. Their operations demonstrate high technical sophistication with an emphasis on persistence, covert C2 and exploitation of known CVEs.
Goals & Targeting
The actor's strategic goal is to acquire signals intelligence from telecommunications payloads, including subscriber data, call metadata and other mission‑critical information. By leveraging weak passwords and exploitable vulnerabilities they infiltrate partner networks, pivot through trusted relationships (telecom vendors, cloud services) and establish multiple layers of persistence and command‑and‑control. Their targeting profile spans nearly every global telecom operator and is extended to any organisation that shares interfaces or contractual obligations with affected carriers.
Enhanced Description
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
LIMINAL PANDA’s activities exhibit a disciplined, long‑term campaign model rather than opportunistic intrusions. The actor has repeatedly compromised major telecom operators in South Asia and Africa, using trusted vendor connections to expand their reach. Their infrastructure leverages commercial cloud hosts (e.g., Vultr) to host C2 nodes and employs chained proxies to obfuscate traffic. Operations tend to occur during off‑peak hours, with daily execution windows tied to specific UTC times. Victim sectors extend beyond telecoms to any organisation connected through shared services or partnerships, especially those providing critical communication infrastructure.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
The available information provides a coherent picture of LIMINAL PANDA’s tactics, techniques and procedures focused on telecommunications networks, but it is largely derived from a single public report and supplementary observations. While the core capabilities are well‑documented, details such as exact campaign chronology, full toolchain spectrum, and broader victim reach remain incomplete. Further intelligence would refine operational timelines, supply chain influences and potential expansion into other sectors.
No campaigns linked yet.
No observed data linked yet.
50
Techniques
48
Tools
0
Campaigns
39
IOCs
0
Observed Data
15
Tactics