Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors Anchor Panda

Also known as: Anchor Panda, ANCHOR PANDA, QAZTeam, ALUMINUM

Description

**Targets:** This threat actor targets government and private sector entities interested in maritime issues in the South China Sea for espionage purposes. Maritime satellite systems, aerospace companies, and defense contractors. **Toolset/Malware:** Adobe Gh0st, Poison Ivy, Torn RAT **Notes:** PdPD (50 64 50 44) marker for encrypted binaries

Goals & Targeting

Targeted Sectors

Government
Defense
Aerospace & defense

Targeted Countries / Regions

CN

AI Analysis

· 1 week ago

Executive Summary

Anchor Panda is a nation-state threat actor primarily engaged in espionage against government, defense, and aerospace entities in China, focusing on maritime issues in the South China Sea. They employ tools like Adobe Gh0st, Poison Ivy, and Torn RAT, and use encrypted binaries with a PdPD marker. Their activities suggest strategic intelligence-gathering linked to geopolitical interests.

Goals & Targeting

Anchor Panda's primary objective is espionage, with a specific focus on sectors and regions critical to China's geopolitical interests, particularly the South China Sea. By targeting government agencies, defense contractors, and aerospace firms, they aim to gather sensitive intelligence on maritime navigation systems, military capabilities, and technological innovations. This targeting profile suggests a strategic intent to support China's territorial claims and enhance its influence in the region. The group's focus on Chinese entities may also reflect an interest in securing internal state secrets or advancing national defense priorities through surveillance and data theft.

Enhanced Description

Anchor Panda, also known as QAZTeam and ALUMINUM, is a sophisticated nation-state group conducting espionage operations targeting government agencies, defense contractors, and aerospace companies in China. Their focus on maritime entities in the South China Sea indicates an interest in intelligence related to territorial disputes, navigation systems, and military capabilities. The group utilizes a range of remote access tools (RATs) and custom malware, with encrypted payloads bearing the PdPD (50 64 50 44) marker, suggesting an emphasis on evading detection. Their operations are highly targeted, indicating advanced reconnaissance and a deep understanding of their victims' infrastructures. The group's activities are likely supported by state resources, enabling them to maintain long-term access to critical systems and exfiltrate sensitive data. Anchor Panda's operations highlight the growing threat of state-sponsored espionage focusing on strategic geographic regions and technology sectors.

Key Capabilities

  • Use of remote access tools (RATs) such as Adobe Gh0st, Poison Ivy, and Torn RAT
  • Encrypted malware with PdPD marker for obfuscation and anti-analysis
  • Advanced social engineering and spear-phishing campaigns targeting maritime and defense sectors
  • Persistence mechanisms to maintain long-term access to victim networks
  • Custom tool development for exfiltrating sensitive data from high-value targets

MITRE ATT&CK Tactics

Initial Access
Execution
Persistence
Exfiltration

ATT&CK Techniques

T1059.003 - Remote Services: RDP
T1055 - Process Injection
T1566.001 - Phishing
T1047 - Windows Management Instrumentation
T1560 - Data Encrypted for Exfiltration

Software / Tooling

Adobe Gh0st
Poison Ivy
Torn RAT
Custom Encryption Tool (PdPD marker)

Campaigns & Victims

Anchor Panda's campaigns are characterized by a focus on maritime and defense entities in China, with operations likely orchestrated over extended periods to avoid detection. Their use of encrypted payloads and custom tools suggests a preference for stealth and operational security. Campaigns may involve initial compromise via spear-phishing, followed by lateral movement and data exfiltration. Limited public information on specific campaigns or timestamps implies that their activities may be sporadic or underreported, with a low operational tempo to reduce risk of exposure.

IOC Patterns

  • Spear-phishing with macro-laced Office documents targeting maritime and defense personnel
  • C2 communication over encrypted channels with domain generation algorithms (DGAs)
  • Use of PdPD (50 64 50 44) marker in encrypted binaries
  • Staging infrastructure on bulletproof hosting services in China
  • Malicious file hashes associated with Adobe Gh0st and Torn RAT

Recommended Actions

  • Implement advanced email filtering and user training to detect and block spear-phishing attempts
  • Deploy endpoint detection and response (EDR) solutions to identify anomalous behavior from RATs like Poison Ivy
  • Monitor for encrypted traffic anomalies and inspect C2 patterns using network traffic analysis tools
  • Conduct regular threat hunting for PdPD-marked binaries and associated malware indicators
  • Restrict lateral movement within networks through zero-trust architectures and least-privilege policies

Suggested Tags

APT
espionage
China
government
defense
aerospace
maritime

Confidence Assessment

Confidence in Anchor Panda's activities is moderate to high, based on the consistent targeting of maritime and defense sectors in China, use of known tools, and presence of unique encryption markers. However, gaps exist in detailed campaign timelines, linked MITRE techniques, and specific IOC data, which could affect the precision of attribution. Additional intelligence on victim compromises or infrastructure details would further validate these findings.

ATT&CK Techniques

No techniques linked yet.

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

No IOCs linked yet.

References

No references recorded yet.

Intel Summary

0

Techniques

3

Tools

0

Campaigns

0

IOCs

0

Observed Data

0

Tactics

Tags

APT
Government Targeting
espionage
China
government
defense
aerospace
maritime

Details

Type
Nation-State
Resource Level
Government
Primary Motivation
Espionage
Country of Origin
China (CN)
Confidence
70%
Added
May 4, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.