Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors JACKPOT PANDA

Also known as: other aliases, several other aliases, Earth Lamia, first identified in 2014, 0mid16B, Cobalt Gang, Slayer Kitten, GOLD HERON, Phantom Panda, Alloy Taurus, Granite Typhoon, Callisto, SEABORGIUM, TA446, Evil Corp, the Latrodectus downloader, the Lotus loader family, Transparent Tribe, APT36, Gold Southfield, SideWinder, APT-C-17, Rattlesnake, APT39, Chafer, Sodinokibi, first observed in 2019, APT37, Selective Pisces, is a sophisticated, governments, MuddyWater, Seedworm, TEMP.Zagros, Mercury, APT26, Volt Typhoon, Bronze Silhouette, DEV-0391, Turla, Snake, Venomous Bear, Group 88, Waterbug, Turla Team, Krypton, Uroburos, SIG23, MAKERSMARK, IRON HUNTER, ALPHV, Gleaming Pisces, BokBot, PlayCrypt, Uroboros, DEV-0832, Vanilla Tempest, is a notorious ransomware, APT15, Ke3chang, CVE-2025-32433, OTP's SSH implementation, the ALPHV Ransomware Group, ALPHV Blackcat, Jumpy Pisces, Comment Crew, MenuPass, Red Apollo, Stone Panda, Gothic Panda, UPS Team, Pirate Panda, Buckeye, Reaper, ScarCruft, APT35, Phosphorus, Ajax Security Team, ITG18, Cozy Bear, APT28, Carbon Spider, GOLD NIAGARA, Sangria Tempest, ITG14, TA505, Hive0065, APT34, OilRig, Chrysene

Description

Jackpot Panda is a sophisticated threat actor with links to China’s public security apparatus. Active since at least May 2020, the group consistently targets organizations involved in online gambling, financial services, healthcare, and government across East and Southeast Asia. Their primary operational vector is exploitation of publicly disclosed web‑application vulnerabilities; most recently they have leveraged React2Shell (CVE‑2025‑55182), a deserialization flaw in React Server Components that allows unauthenticated remote code execution on Next.js sites. Upon gaining initial foothold, the attackers deploy a mixed arsenal of commercial and custom malware. Commercial RATs such as Cobalt Strike, Sliver, and Vshell are used for command‑and‑control and lateral movement, while the Mustang Panda kernel rootkit provides privileged persistence. They also use webshells, malicious VSCode extensions, and supply‑chain compromises to deliver secondary payloads, including ransomware families (Lockbit, Medusa, PlayCrypt) via double‑extortion tactics. In addition to espionage, Jackpot Panda employs credential harvesting tools and legitimate administrative utilities for lateral movement. The group has demonstrated a rapid exploitation cycle—identifying newly disclosed vulnerabilities within days of publication—and uses compromised IoT devices to mask C2 traffic (Operational Relay Boxes). Their operations are tailored to gather intelligence supporting domestic security priorities while occasionally extracting financial gains through ransomware. Overall, Jackpot Panda’s blend of zero‑day exploitation, supply‐chain attacks, and sophisticated backdoor deployment makes it a credible asset for state‑level espionage against the gambling sector and other high‑value targets in the region.

Goals & Targeting

Targeted Sectors

Financial services
Government
Defense
Healthcare
Telecommunications
Critical infrastructure
Education
Media
Manufacturing
Energy
Aerospace
Hospitality
Retail
Non profit
Maritime
Gaming
Aviation
Transportation
Think tank
Legal services
Utilities
Information technology
Nuclear
Entertainment
Food agriculture
Construction
Mining

Targeted Countries / Regions

CN
RU
IR
IN
KP
UA
US
BR
GB
KR
PK
DE
TR
VN
BY
PL
TW
CA
AU

AI Analysis

Grounded in web research
· analyzed in 69 chunks · 5 days ago

Executive Summary

Jackpot Panda is a Chinese‑state‐aligned APT group that has been exploiting public web–application vulnerabilities—most notably the React2Shell CVE‑2025‑55182—in order to gain initial access to high‑value East and Southeast Asian targets, including online gambling operators and domestic security entities. The actors quickly deploy commercial RATs (Cobalt Strike, Sliver, Vshell) and custom backdoors such as Mustang Panda for persistence, lateral movement, and data exfiltration while also engaging in double‑extortion ransomware activity when appropriate.

Goals & Targeting

Jackpot Panda’s strategic objectives are two‑fold: first, to conduct intelligence gathering on entities that influence China’s domestic security and financial information—including online gambling operators and their payment infrastructures—and second, to leverage collected data for economic coercion through double‑extortion ransomware. Their targeting profile focuses on East and Southeast Asian organizations with exposed public web interfaces or critical payment systems, exploiting the rapid exploitation timeline of newly disclosed vulnerabilities to maximize stealth and impact. The actor’s operational tempo is characterized by swift identification of zero‑day or high‑severity CVEs, automated scanning for vulnerable assets, followed by manual “breakout” phases that pivot from the compromised webserver into internal networks. This pattern is consistent with state‑level espionage objectives while aligning with financial incentives.

Enhanced Description

Key Capabilities

  • Exploitation of publicly disclosed web application vulnerabilities (e.g., React2Shell CVE-2025-55182) for initial access
  • Rapid deployment of commercial RATs and custom backdoors such as Cobalt Strike, Sliver, Vshell, Mustang Panda kernel rootkit, XAgent
  • Watering‑hole attacks via compromised vendor or open‑source components, including malicious VSCode extensions
  • Supply chain compromise to deliver trojanized installers (e.g., CloudChat) into target environments
  • Exploitation of deserialization flaws in React Server Components for remote code execution
  • Deployment of webshells on public servers providing persistence and pivot capability
  • Use of credential harvesting tools (IcedID, Dridex, Emotet) and legitimate administrative utilities for lateral movement
  • Double‑extortion ransomware activity with data exfiltration prior to encryption (Lockbit, Medusa, PlayCrypt)
  • Pivoting via compromised IoT devices used as Operational Relay Boxes (ORB) to obfuscate command‑and‑control traffic

MITRE ATT&CK Tactics

Initial Access
Execution
Command and Control
Persistence
Privilege Escalation
Defense Evasion
Lateral Movement
Discovery
Collection
Exfiltration/Collection
Credential Access
Impact

ATT&CK Techniques

T1190
T1041
T1105
T1203
T1189
T1195
T1566
T1195.001
T1566.002
T1003
T1078
T1086
T1486
T1566.001
T1204
T1195.002
T1068
T1059.001
T1490
T1059.003
T1087
T1496
T1133
T1657
T1021.001
T1020
T1074
T1110.001
T1071.001
T1090

Software / Tooling

Cobalt Strike
Sliver
Vshell
Mustang Panda backdoor
XAgent
Dridex
IcedID
BokBot
BianLian Ransomware
Lockbit Ransomware
Medusa Ransomware
Netwalker RaaS
PlayCrypt Ransomware
GandCrab Ransomware
REvil Ransomware
Emotet
Monarch Spider exploit broker
Defray777
Locky
Cactus Ransomware
Strigoi Master
RegXploit
Zeppelin
Hello Kitty
Ragnar Locker
Black Basta
DoppelPaymer
TrickBot
Conti Ransomware
XMRig
Sidecopy (infostealer)
CloudChat trojanized installer
UltraVNC
Remote Manipulator System (RMS)

Campaigns & Victims

Jackpot Panda consistently demonstrates an operational pattern that begins with automated scanning for publicly exposed web applications, followed by exploiting a newly disclosed vulnerability within hours of its public disclosure—a behavior mirrored in other Chinese state‑nexus groups such as Earth Lamia. Once initial foothold is achieved via React2Shell or similar exploits, the actor stages a multi‑stage intrusion: deploying a persistent backdoor (Mustang Panda or Cobalt Strike), planting webshells for lateral movement, harvesting credentials with tools like IcedID, and finally executing double‑extortion campaigns when valuable data is detected. Victim organizations are typically high‑profile entities in the online gambling sector, financial services, healthcare, government, and critical infrastructure within East and Southeast Asia. The group’s campaign tempo is rapid; reports indicate dozens of exploitation attempts against CVE‑2025-55182 within a single day from disparate IP ranges. Evidence also shows use of Operational Relay Boxes built on compromised IoT devices to mask outbound traffic, indicating both sophistication in evasion and reliance on commodity infrastructure.

IOC Patterns

  • CVE-2025-55182 (React2Shell) exploitation attempts via multipart/form-data with : and $ characters
  • Deployment of malicious VSCode extensions for supply‑chain delivery
  • Use of signed binaries from legitimate vendors to evade detection
  • Installation of Mustang Panda kernel rootkit signatures on Linux hosts
  • Webshell artifacts in public web directories
  • Cobalt Strike Beacon command‑and‑control traffic patterns
  • Operational Relay Box fingerprints (e.g., known IoT IP ranges)
  • Credential dumping events from XAgent
  • Exfiltration traffic containing encrypted data archives
  • Watering‑hole logs indicating access to vendor update pages

Recommended Actions

  • Patch and harden all React, Next.js, Vite, and related frameworks against CVE-2025-55182 and related RSC vulnerabilities immediately; validate with safe curl probes.
  • Deploy WAF rules or Web Application Firewalls that block multipart/form-data requests containing colon (:) delimiters and dollar sign ($) references targeting RSC endpoints.
  • Implement strict audit and logging of web server processes to detect anomalous whoami executions or child_process.execSync calls.
  • Vetting policy for VSCode extensions: only allow official, signed extensions from approved vendors; disable unknown extensions.
  • Deploy EDR/NDM solutions capable of detecting Cobalt Strike, Sliver, Vshell beacon activity and Mustang Panda backdoor indicators.
  • Segment DMZ-hosted web servers from internal networks; apply egress filtering to restrict outbound traffic to required services only.
  • Apply multi‑factor authentication for remote access tools (RDP, VNC, RMS) and enforce least privilege on administrative accounts.
  • Establish backup integrity verification procedures and separate backup storage from production systems.
  • Use data loss prevention (DLP) solutions to monitor for exfiltration of sensitive files or encrypted payloads.
  • Run regular threat hunting queries focused on known RhoP/React2Shell indicator patterns and supply‑chain compromise signatures.

Software / Tooling

Observed Data

No observed data linked yet.

Indicators of Compromise

Domain 11 Filename 9

References

  1. www.huntress.com — Cited by web research for: other aliases
  2. unit42.paloaltonetworks.com — Cited by web research for: T1486
  3. www.huntress.com — Cited by web research for: phishing
  4. www.sentinelone.com — Cited by web research for: Singularity
  5. businessinsights.bitdefender.com — Cited by web research for: Node.js
  6. www.cybereason.com — Cited by web research for: CVE-2025-32433
  7. www.recordedfuture.com — Cited by web research for: CVE-2025-20393

Intel Summary

7

Techniques

66

Tools

7

Campaigns

40

IOCs

0

Observed Data

5

Tactics

Tags

APT
Cyber espionage
State-sponsored threat
East Asia
Southeast Asia
Online Gambling Sector

Details

Type
Unknown
Resource Level
Government
Primary Motivation
Financial gain
Country of Origin
C
Confidence
60%
Added
Jul 27, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.