**Targets:** Financial services firms **Notes:** Mentioned by Alperovitch in 2013 article as targeting financial services industry
Targeted Sectors
Executive Summary
Big Panda is a nation-state threat actor primarily motivated by financial gain. Targeting the financial services sector, Big Panda employs advanced tactics to infiltrate organizations, exfiltrate sensitive data, and potentially disrupt operations. Their activities suggest a high level of sophistication, making them a significant threat to global financial institutions.
Goals & Targeting
Big Panda's primary goal is to achieve financial gain through the theft of sensitive data and potential disruption of financial services. Their targeting of financial institutions suggests an interest in high-value assets, such as customer credentials, transaction records, or proprietary information. The group likely prioritizes sectors where stolen data can be monetized most effectively. Given their nation-state origin, Big Panda may also have strategic interests in the economic stability of specific countries or regions.
Enhanced Description
Big Panda is a financially motivated nation-state actor that has been observed targeting the financial services sector. The group likely focuses on stealing sensitive information, such as customer data or intellectual property, which can be monetized through sale on dark web marketplaces or used for extortion. Big Panda's operational style includes using advanced persistent threat (APT) techniques to gain long-term access to targeted networks. Their tactics may involve initial compromises via phishing campaigns or vulnerabilities in third-party suppliers, followed by lateral movement within the network and credential harvesting. The group’s activities resemble those of other financially motivated APTs that target financial institutions for profit.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
Big Panda's campaigns likely target financial institutions globally, with a focus on long-term access to networks. Their operational tempo suggests a patient approach, indicating they are willing to wait for high-value targets. Notable patterns include the use of spear-phishing emails, malware deployment, and persistent backdoors to maintain access. The group’s activities resemble those of other APTs targeting financial services, such as Operation Trident Breach.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
Moderate confidence in Big Panda's nation-state classification and financial motivation based on available indicators. Limited visibility into specific campaigns or tools used by the group creates uncertainty, particularly regarding their exact targeting patterns and TTPs. Further analysis of linked IOCs and associated campaigns would improve understanding.
No techniques linked yet.
No tools linked yet.
No campaigns linked yet.
No observed data linked yet.
No IOCs linked yet.
No references recorded yet.
0
Techniques
0
Tools
0
Campaigns
0
IOCs
0
Observed Data
0
Tactics