Also known as: Maverick Panda, PLA Navy, Sykipot, Wisp Team, MAVERICK PANDA, BRONZE EDISON, SODIUM, Salmon Typhoon, APT4, Samurai Panda, network, software application, OilRig, tracked as, email beacons, web beacons, are small, invisible images, a botnet, root access
Maverick Panda (also known as APT4, Wisp Team, Sykipot, and the PLA Navy’s Shadow Panda) is an advanced threat group linked to the People’s Liberation Army. The actor’s primary objective is espionage against strategic targets, particularly those connected to Taiwan, Hong Kong, Tibet, and Uyghur interests. Their campaigns often start with carefully crafted spear‑phishing emails bearing malicious attachments or link shorteners that trigger a zero‑day exploit or drive download of a custom RAT. Once inside, the malware portfolio includes PlugX for persistence, Gh0StRAT and Agent.XST for lateral movement, as well as newer variants such as UP007, SLServer, Grabber, T9000 and Kivars. The group combines these with credential‑dumping modules (e.g., LSASS memory extraction) and employs domain-based command‑and‑control infrastructure frequently hosted on bulletproof hosting providers. They also integrate cryptocurrency mining payloads—most notably XMRig—to monetize compromised infrastructure. Maverick Panda has demonstrated an ability to pivot across sectors: government, defense, critical infrastructure, telecommunications, financial services, manufacturing, aviation, aerospace, IT, non‑profit, media, nuclear, maritime, gaming, mining, oil & gas and healthcare. Their operations span multiple continents, with documented activity targeting the U.S., Taiwan, Japan, South Korea, Germany and the UK. The group’s “Four Element Sword” campaign illustrates a coordinated effort focused on data exfiltration from defense contractors; other identified campaigns include INOCNATION, Poisoned Helmand, Titan Rain, Sykipot operations, Getkys, Wyksol, Honeybee, Mermaid, Big Bang and Groundbait.
Active
Targeted Sectors
Targeted Countries / Regions
Executive Summary
Maverick Panda is a Chinese nation‑state threat actor, operating under several aliases such as APT4, Wisp Team and Sykipot. The group specializes in sophisticated spear‑phishing campaigns targeting U.S., Asian and Middle Eastern governments, defense contractors and critical infrastructure, largely for espionage against political, military, and strategic interests. Their arsenal includes custom malware like PlugX and Gh0StRAT combined with widely used tools such as XMRig for cryptojacking.
Goals & Targeting
The strategic aim of Maverick Panda is to acquire actionable intelligence on political, military and economic entities that impact China’s regional influence—especially those tied to Taiwan, Hong Kong and ethnic minorities such as Uyghurs. By infiltrating defense contractors, aerospace firms, critical infrastructure operators and telecom companies they seek detailed technical specifications, operational plans, and sensitive communications. Typically, their victims are large multi‑national corporations with global supply chains, U.S. Department of Defense contractors, aviation authorities and organizations deemed strategic to geopolitical objectives.
Enhanced Description
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
Maverick Panda’s activity is characterized by high‑frequency, long‑duration campaigns that typically begin with a targeted spear‑phishing wave and evolve into multi‑stage intrusion sequences. The Four Element Sword operation revealed coordinated data theft from defense supply chains; INOCNATION appeared to focus on industrial control system reconnaissance. Their operational tempo often mirrors strategic events in the Asia‑Pacific region, leveraging zero‑day vulnerabilities when available. Victims tend to be high‑profile entities whose compromise would yield actionable trade‑secret or classified information.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
The intelligence is drawn primarily from publicly available threat actor cards and security blog posts, providing a coherent picture of Maverick Panda’s tactics, techniques, and objectives. However, the data lacks recent timestamped activity beyond 2024, limiting insight into current operational tempo or evolving capabilities — the latest documented campaign is Four Element Sword from 2019‑2020. Consequently confidence in ongoing activity and potential use of newer malware is moderate; further on‑ground or up‑to‑date threat intelligence would refine these assessments.
Four Element Sword
INOCNATION
Poisoned Helmand
Titan Rain
Sykipot, Getkys, Wyksol
Honeybee
Mermaid
Big Bang
Groundbait
IronGate
Olympic Destroyer
No observed data linked yet.
11
Techniques
55
Tools
11
Campaigns
39
IOCs
0
Observed Data
3
Tactics