Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors Maverick Panda

Also known as: Maverick Panda, PLA Navy, Sykipot, Wisp Team, MAVERICK PANDA, BRONZE EDISON, SODIUM, Salmon Typhoon, APT4, Samurai Panda, network, software application, OilRig, tracked as, email beacons, web beacons, are small, invisible images, a botnet, root access

Description

Maverick Panda (also known as APT4, Wisp Team, Sykipot, and the PLA Navy’s Shadow Panda) is an advanced threat group linked to the People’s Liberation Army. The actor’s primary objective is espionage against strategic targets, particularly those connected to Taiwan, Hong Kong, Tibet, and Uyghur interests. Their campaigns often start with carefully crafted spear‑phishing emails bearing malicious attachments or link shorteners that trigger a zero‑day exploit or drive download of a custom RAT. Once inside, the malware portfolio includes PlugX for persistence, Gh0StRAT and Agent.XST for lateral movement, as well as newer variants such as UP007, SLServer, Grabber, T9000 and Kivars. The group combines these with credential‑dumping modules (e.g., LSASS memory extraction) and employs domain-based command‑and‑control infrastructure frequently hosted on bulletproof hosting providers. They also integrate cryptocurrency mining payloads—most notably XMRig—to monetize compromised infrastructure. Maverick Panda has demonstrated an ability to pivot across sectors: government, defense, critical infrastructure, telecommunications, financial services, manufacturing, aviation, aerospace, IT, non‑profit, media, nuclear, maritime, gaming, mining, oil & gas and healthcare. Their operations span multiple continents, with documented activity targeting the U.S., Taiwan, Japan, South Korea, Germany and the UK. The group’s “Four Element Sword” campaign illustrates a coordinated effort focused on data exfiltration from defense contractors; other identified campaigns include INOCNATION, Poisoned Helmand, Titan Rain, Sykipot operations, Getkys, Wyksol, Honeybee, Mermaid, Big Bang and Groundbait.

TTP Summary

Active

Goals & Targeting

Targeted Sectors

Government
Defense
Critical infrastructure
Telecommunications
Financial services
Critical infrastructure
Manufacturing
Aviation
Aerospace
Information technology
Non profit
Media
Nuclear
Maritime
Gaming
Mining
Oil gas
Healthcare
Energy

Targeted Countries / Regions

TW
US
IR
middle_east
KR
CN
DE
GB

AI Analysis

Grounded in web research
· 1 day ago

Executive Summary

Maverick Panda is a Chinese nation‑state threat actor, operating under several aliases such as APT4, Wisp Team and Sykipot. The group specializes in sophisticated spear‑phishing campaigns targeting U.S., Asian and Middle Eastern governments, defense contractors and critical infrastructure, largely for espionage against political, military, and strategic interests. Their arsenal includes custom malware like PlugX and Gh0StRAT combined with widely used tools such as XMRig for cryptojacking.

Goals & Targeting

The strategic aim of Maverick Panda is to acquire actionable intelligence on political, military and economic entities that impact China’s regional influence—especially those tied to Taiwan, Hong Kong and ethnic minorities such as Uyghurs. By infiltrating defense contractors, aerospace firms, critical infrastructure operators and telecom companies they seek detailed technical specifications, operational plans, and sensitive communications. Typically, their victims are large multi‑national corporations with global supply chains, U.S. Department of Defense contractors, aviation authorities and organizations deemed strategic to geopolitical objectives.

Enhanced Description

Key Capabilities

  • Advanced spear‑phishing campaigns using zero‑day exploits
  • Credential dumping via LSASS memory extraction (T1003.001)
  • Persistent backdoors such as PlugX, Gh0StRAT, Agent.XST
  • Use of custom RATs and well‑known malware families
  • Command & Control over obfuscated domains and bulletproof hosting
  • Cryptocurrency mining with XMRig for monetization
  • Lateral movement across Windows networks
  • Defense evasion through masquerading and silent persistence

MITRE ATT&CK Tactics

Initial Access
Execution
Persistence
Privilege Escalation
Defense Evasion
Credential Access
Collection
Command And Control
Exfiltration

ATT&CK Techniques

T1204.002 Malicious File
T1003.001 LSASS Memory
T1204.004 Malicious Copy and Paste
T1059.003 PowerShell
T1071.001 Application Layer Protocol: HTTP
T1105 Ingress Tool Transfer
T1140 Deobfuscate/Decode Files or Information
T1036 Masquerading

Software / Tooling

UP007
SLServer
Grabber
T9000
Kivars
PlugX
Gh0StRAT
Agent.XST
XMRig

Campaigns & Victims

Maverick Panda’s activity is characterized by high‑frequency, long‑duration campaigns that typically begin with a targeted spear‑phishing wave and evolve into multi‑stage intrusion sequences. The Four Element Sword operation revealed coordinated data theft from defense supply chains; INOCNATION appeared to focus on industrial control system reconnaissance. Their operational tempo often mirrors strategic events in the Asia‑Pacific region, leveraging zero‑day vulnerabilities when available. Victims tend to be high‑profile entities whose compromise would yield actionable trade‑secret or classified information.

IOC Patterns

  • Spear‑phishing emails with macro‑laden Office documents
  • Obfuscated malicious files delivered via email or infected websites
  • C2 domains using random sub‑domains (e.g., aqdrmf-…) and dynamic DNS records
  • Bulletproof hosting providers used for command servers
  • Pixel beacon 1x1 tracking images embedded in phishing emails
  • Use of compromised legitimate services for exfiltration

Recommended Actions

  • Implement mandatory email filtering with granular attachment sanitization and sandbox analysis for suspicious files
  • Conduct regular user training focused on spear‑phishing and macro awareness
  • Apply patches promptly, especially for known zero‑day exploit CVEs used by the group
  • Deploy endpoint detection and response tools capable of detecting LSASS memory dumps and persistent RATs
  • Block outbound connections to known malicious domains and enforce strict DNS filtering
  • Implement multi‑factor authentication throughout critical internal systems
  • Perform regular red‑team assessments simulating nation‑state spear‑phishing attacks

Suggested Tags

APT
Espionage
Nation‑State
China
Government Targeting
Defense Contractor
Critical Infrastructure
Spear Phishing
Malware
Cryptocurrency Mining

Confidence Assessment

The intelligence is drawn primarily from publicly available threat actor cards and security blog posts, providing a coherent picture of Maverick Panda’s tactics, techniques, and objectives. However, the data lacks recent timestamped activity beyond 2024, limiting insight into current operational tempo or evolving capabilities — the latest documented campaign is Four Element Sword from 2019‑2020. Consequently confidence in ongoing activity and potential use of newer malware is moderate; further on‑ground or up‑to‑date threat intelligence would refine these assessments.

Software / Tooling

Observed Data

No observed data linked yet.

Indicators of Compromise

Domain 20

References

  1. www.malwarebytes.com — Cited by web research for: network
  2. www.cybereason.com — Cited by web research for: phishing
  3. www.sentinelone.com — Cited by web research for: Singularity
  4. apt.etda.or.th — Cited by web research for: XMRIG
  5. apt.etda.or.th — Cited by web research for: Information Technology
  6. cloud.google.com — Cited by web research for: aqdrmf-rymPhb-ibnC6b.aqdrmf
  7. https://malpedia.caad.fkie.fraunhofer.de/actor/apt14 — Cited by AI analysis.
  8. https://blog.trendmicro.com/trendlabs-security-intelligence/sykipot-now-targeting-us-civil-aviation-sector-information/ — Cited by AI analysis.
  9. https://www.microsoft.com/en-us/security/blog/2024/02/14/staying-ahead-of-threat-actors-in-the-age-of-ai/ — Cited by AI analysis.

Intel Summary

11

Techniques

55

Tools

11

Campaigns

39

IOCs

0

Observed Data

3

Tactics

Tags

APT
espionage
government
infrastructure
Espionage
Nation‑State
China
Government Targeting
Defense Contractor
Critical Infrastructure
Spear Phishing
Malware
Cryptocurrency Mining

Details

MITRE ID
APT4
Type
Nation-State
Resource Level
Government
Primary Motivation
Espionage
Country of Origin
China (CN)
Confidence
70%
Added
Jul 21, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.