Also known as: Anchor Panda, ANCHOR PANDA, QAZTeam, ALUMINUM
**Targets:** This threat actor targets government and private sector entities interested in maritime issues in the South China Sea for espionage purposes. Maritime satellite systems, aerospace companies, and defense contractors. **Toolset/Malware:** Adobe Gh0st, Poison Ivy, Torn RAT **Notes:** PdPD (50 64 50 44) marker for encrypted binaries
Targeted Sectors
Targeted Countries / Regions
Executive Summary
Anchor Panda is a nation-state threat actor primarily engaged in espionage against government, defense, and aerospace entities in China, focusing on maritime issues in the South China Sea. They employ tools like Adobe Gh0st, Poison Ivy, and Torn RAT, and use encrypted binaries with a PdPD marker. Their activities suggest strategic intelligence-gathering linked to geopolitical interests.
Goals & Targeting
Anchor Panda's primary objective is espionage, with a specific focus on sectors and regions critical to China's geopolitical interests, particularly the South China Sea. By targeting government agencies, defense contractors, and aerospace firms, they aim to gather sensitive intelligence on maritime navigation systems, military capabilities, and technological innovations. This targeting profile suggests a strategic intent to support China's territorial claims and enhance its influence in the region. The group's focus on Chinese entities may also reflect an interest in securing internal state secrets or advancing national defense priorities through surveillance and data theft.
Enhanced Description
Anchor Panda, also known as QAZTeam and ALUMINUM, is a sophisticated nation-state group conducting espionage operations targeting government agencies, defense contractors, and aerospace companies in China. Their focus on maritime entities in the South China Sea indicates an interest in intelligence related to territorial disputes, navigation systems, and military capabilities. The group utilizes a range of remote access tools (RATs) and custom malware, with encrypted payloads bearing the PdPD (50 64 50 44) marker, suggesting an emphasis on evading detection. Their operations are highly targeted, indicating advanced reconnaissance and a deep understanding of their victims' infrastructures. The group's activities are likely supported by state resources, enabling them to maintain long-term access to critical systems and exfiltrate sensitive data. Anchor Panda's operations highlight the growing threat of state-sponsored espionage focusing on strategic geographic regions and technology sectors.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
Anchor Panda's campaigns are characterized by a focus on maritime and defense entities in China, with operations likely orchestrated over extended periods to avoid detection. Their use of encrypted payloads and custom tools suggests a preference for stealth and operational security. Campaigns may involve initial compromise via spear-phishing, followed by lateral movement and data exfiltration. Limited public information on specific campaigns or timestamps implies that their activities may be sporadic or underreported, with a low operational tempo to reduce risk of exposure.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
Confidence in Anchor Panda's activities is moderate to high, based on the consistent targeting of maritime and defense sectors in China, use of known tools, and presence of unique encryption markers. However, gaps exist in detailed campaign timelines, linked MITRE techniques, and specific IOC data, which could affect the precision of attribution. Additional intelligence on victim compromises or infrastructure details would further validate these findings.
No techniques linked yet.
No campaigns linked yet.
No observed data linked yet.
No IOCs linked yet.
No references recorded yet.
0
Techniques
3
Tools
0
Campaigns
0
IOCs
0
Observed Data
0
Tactics