Also known as: other aliases, several other aliases, Earth Lamia, first identified in 2014, 0mid16B, Cobalt Gang, Slayer Kitten, GOLD HERON, Phantom Panda, Alloy Taurus, Granite Typhoon, Callisto, SEABORGIUM, TA446, Evil Corp, the Latrodectus downloader, the Lotus loader family, Transparent Tribe, APT36, Gold Southfield, SideWinder, APT-C-17, Rattlesnake, APT39, Chafer, Sodinokibi, first observed in 2019, APT37, Selective Pisces, is a sophisticated, governments, MuddyWater, Seedworm, TEMP.Zagros, Mercury, APT26, Volt Typhoon, Bronze Silhouette, DEV-0391, Turla, Snake, Venomous Bear, Group 88, Waterbug, Turla Team, Krypton, Uroburos, SIG23, MAKERSMARK, IRON HUNTER, ALPHV, Gleaming Pisces, BokBot, PlayCrypt, Uroboros, DEV-0832, Vanilla Tempest, is a notorious ransomware, APT15, Ke3chang, CVE-2025-32433, OTP's SSH implementation, the ALPHV Ransomware Group, ALPHV Blackcat, Jumpy Pisces, Comment Crew, MenuPass, Red Apollo, Stone Panda, Gothic Panda, UPS Team, Pirate Panda, Buckeye, Reaper, ScarCruft, APT35, Phosphorus, Ajax Security Team, ITG18, Cozy Bear, APT28, Carbon Spider, GOLD NIAGARA, Sangria Tempest, ITG14, TA505, Hive0065, APT34, OilRig, Chrysene
Jackpot Panda is a sophisticated threat actor with links to China’s public security apparatus. Active since at least May 2020, the group consistently targets organizations involved in online gambling, financial services, healthcare, and government across East and Southeast Asia. Their primary operational vector is exploitation of publicly disclosed web‑application vulnerabilities; most recently they have leveraged React2Shell (CVE‑2025‑55182), a deserialization flaw in React Server Components that allows unauthenticated remote code execution on Next.js sites. Upon gaining initial foothold, the attackers deploy a mixed arsenal of commercial and custom malware. Commercial RATs such as Cobalt Strike, Sliver, and Vshell are used for command‑and‑control and lateral movement, while the Mustang Panda kernel rootkit provides privileged persistence. They also use webshells, malicious VSCode extensions, and supply‑chain compromises to deliver secondary payloads, including ransomware families (Lockbit, Medusa, PlayCrypt) via double‑extortion tactics. In addition to espionage, Jackpot Panda employs credential harvesting tools and legitimate administrative utilities for lateral movement. The group has demonstrated a rapid exploitation cycle—identifying newly disclosed vulnerabilities within days of publication—and uses compromised IoT devices to mask C2 traffic (Operational Relay Boxes). Their operations are tailored to gather intelligence supporting domestic security priorities while occasionally extracting financial gains through ransomware. Overall, Jackpot Panda’s blend of zero‑day exploitation, supply‐chain attacks, and sophisticated backdoor deployment makes it a credible asset for state‑level espionage against the gambling sector and other high‑value targets in the region.
Targeted Sectors
Targeted Countries / Regions
Executive Summary
Jackpot Panda is a Chinese‑state‐aligned APT group that has been exploiting public web–application vulnerabilities—most notably the React2Shell CVE‑2025‑55182—in order to gain initial access to high‑value East and Southeast Asian targets, including online gambling operators and domestic security entities. The actors quickly deploy commercial RATs (Cobalt Strike, Sliver, Vshell) and custom backdoors such as Mustang Panda for persistence, lateral movement, and data exfiltration while also engaging in double‑extortion ransomware activity when appropriate.
Goals & Targeting
Jackpot Panda’s strategic objectives are two‑fold: first, to conduct intelligence gathering on entities that influence China’s domestic security and financial information—including online gambling operators and their payment infrastructures—and second, to leverage collected data for economic coercion through double‑extortion ransomware. Their targeting profile focuses on East and Southeast Asian organizations with exposed public web interfaces or critical payment systems, exploiting the rapid exploitation timeline of newly disclosed vulnerabilities to maximize stealth and impact. The actor’s operational tempo is characterized by swift identification of zero‑day or high‑severity CVEs, automated scanning for vulnerable assets, followed by manual “breakout” phases that pivot from the compromised webserver into internal networks. This pattern is consistent with state‑level espionage objectives while aligning with financial incentives.
Enhanced Description
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
Jackpot Panda consistently demonstrates an operational pattern that begins with automated scanning for publicly exposed web applications, followed by exploiting a newly disclosed vulnerability within hours of its public disclosure—a behavior mirrored in other Chinese state‑nexus groups such as Earth Lamia. Once initial foothold is achieved via React2Shell or similar exploits, the actor stages a multi‑stage intrusion: deploying a persistent backdoor (Mustang Panda or Cobalt Strike), planting webshells for lateral movement, harvesting credentials with tools like IcedID, and finally executing double‑extortion campaigns when valuable data is detected. Victim organizations are typically high‑profile entities in the online gambling sector, financial services, healthcare, government, and critical infrastructure within East and Southeast Asia. The group’s campaign tempo is rapid; reports indicate dozens of exploitation attempts against CVE‑2025-55182 within a single day from disparate IP ranges. Evidence also shows use of Operational Relay Boxes built on compromised IoT devices to mask outbound traffic, indicating both sophistication in evasion and reliance on commodity infrastructure.
IOC Patterns
Recommended Actions
Satellite Turla
Epic Turla
The 'Penquin' Turla
Witchcoven
RUAG hack
Mosquito
Moonlight Maze
No observed data linked yet.
7
Techniques
66
Tools
7
Campaigns
40
IOCs
0
Observed Data
5
Tactics