Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors Big Panda

Description

**Targets:** Financial services firms **Notes:** Mentioned by Alperovitch in 2013 article as targeting financial services industry

Goals & Targeting

Targeted Sectors

Financial services

AI Analysis

· 1 week ago

Executive Summary

Big Panda is a nation-state threat actor primarily motivated by financial gain. Targeting the financial services sector, Big Panda employs advanced tactics to infiltrate organizations, exfiltrate sensitive data, and potentially disrupt operations. Their activities suggest a high level of sophistication, making them a significant threat to global financial institutions.

Goals & Targeting

Big Panda's primary goal is to achieve financial gain through the theft of sensitive data and potential disruption of financial services. Their targeting of financial institutions suggests an interest in high-value assets, such as customer credentials, transaction records, or proprietary information. The group likely prioritizes sectors where stolen data can be monetized most effectively. Given their nation-state origin, Big Panda may also have strategic interests in the economic stability of specific countries or regions.

Enhanced Description

Big Panda is a financially motivated nation-state actor that has been observed targeting the financial services sector. The group likely focuses on stealing sensitive information, such as customer data or intellectual property, which can be monetized through sale on dark web marketplaces or used for extortion. Big Panda's operational style includes using advanced persistent threat (APT) techniques to gain long-term access to targeted networks. Their tactics may involve initial compromises via phishing campaigns or vulnerabilities in third-party suppliers, followed by lateral movement within the network and credential harvesting. The group’s activities resemble those of other financially motivated APTs that target financial institutions for profit.

Key Capabilities

  • Advanced persistent threat (APT) techniques
  • Spear-phishing campaigns
  • Exploitation of vulnerabilities
  • Credential harvesting
  • Lateral movement within networks
  • Data exfiltration
  • Disruption of financial operations

MITRE ATT&CK Tactics

Initial Access
Execution
Credential Access
Discovery
Lateral Movement
Collection
Exfiltration
Impact

ATT&CK Techniques

T1059.003
T1078
T1214
T1566.001
T1547.001
T1070
T1512

Software / Tooling

Mimikatz (credential dumping)
Cobalt Strike (C2 framework)
Custom malware for lateral movement
Phishing tools (e.g., email spoofing)

Campaigns & Victims

Big Panda's campaigns likely target financial institutions globally, with a focus on long-term access to networks. Their operational tempo suggests a patient approach, indicating they are willing to wait for high-value targets. Notable patterns include the use of spear-phishing emails, malware deployment, and persistent backdoors to maintain access. The group’s activities resemble those of other APTs targeting financial services, such as Operation Trident Breach.

IOC Patterns

  • Phishing emails impersonating financial institution employees
  • Use of malicious Office documents with embedded scripts
  • Exfiltration via encrypted channels or non-standard protocols
  • Presence of custom malware on financial systems
  • Sustained network persistence over extended periods

Recommended Actions

  • Implement robust email filtering and phishing detection mechanisms.
  • Monitor for unusual lateral movement patterns in networks.
  • Use endpoint detection and response (EDR) solutions to detect credential harvesting.
  • Segment critical financial systems from general network access.
  • Conduct regular penetration testing targeting financial services infrastructure.

Suggested Tags

Nation-state
Financial gain
Cyber espionage
Financial sector
APT
Ransomware

Confidence Assessment

Moderate confidence in Big Panda's nation-state classification and financial motivation based on available indicators. Limited visibility into specific campaigns or tools used by the group creates uncertainty, particularly regarding their exact targeting patterns and TTPs. Further analysis of linked IOCs and associated campaigns would improve understanding.

ATT&CK Techniques

No techniques linked yet.

Software / Tooling

No tools linked yet.

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

No IOCs linked yet.

References

No references recorded yet.

Intel Summary

0

Techniques

0

Tools

0

Campaigns

0

IOCs

0

Observed Data

0

Tactics

Tags

APT
Nation-state
Financial gain
Cyber espionage
Financial sector
Ransomware

Details

Type
Nation-State
Resource Level
Government
Primary Motivation
Financial gain
Country of Origin
China (CN)
Confidence
70%
Added
May 4, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.