Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started

Also known as: Maverick Panda, PLA Navy, Sykipot, root access, AKA, a botnet

Description

**Targets:** Tibetans, Hong Kong, Taiwanese interests and human rights workers, Uyghur Interests **Toolset/Malware:** UP007, SLServer, Grabber, T9000, Kivars, PlugX, Gh0StRAT, Agent.XST **Modus Operandi:** Active **Operations:** Four Element Sword **Overlaps with:** IXESHE (see PWC report)

TTP Summary

Active

Goals & Targeting

Targeted Sectors

Government
Defense
Critical infrastructure
Financial services
Telecommunications
Critical infrastructure
Aviation
Nuclear
Aerospace
Information technology
Manufacturing
Transportation
Maritime
Gaming
Mining
Media
Oil gas
Healthcare
Energy

Targeted Countries / Regions

TW
US
IR
middle_east
KR
DE
CN

AI Analysis

No AI analysis yet.

Software / Tooling

Observed Data

No observed data linked yet.

References

  1. www.malwarebytes.com — Cited by web research for: root access
  2. www.sentinelone.com — Cited by web research for: Singularity
  3. www.cybereason.com — Cited by web research for: STOP
  4. apt.etda.or.th — Cited by web research for: XMRIG
  5. apt.etda.or.th — Cited by web research for: TEMP.Bottle

Intel Summary

5

Techniques

53

Tools

11

Campaigns

4

IOCs

0

Observed Data

3

Tactics

Details

Type
Nation-State
Resource Level
Government
Primary Motivation
Espionage
Country of Origin
China (CN)
Confidence
70%
Added
Aug 10, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.