Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors Judgement Panda

Description

**Targets:** Upstream providers (e.g., law firms and managed service providers) to support additional intrusions against high-profile assets **Toolset/Malware:** Spear-phishing, URL “web bugs” and scheduled tasks to automate credential harvesting

AI Analysis

· 1 week ago

Executive Summary

Judgement Panda is a nation-state threat actor primarily engaged in espionage activities targeting upstream providers such as law firms and managed service providers (MSPs). The group leverages spear-phishing, URL web bugs, and scheduled tasks to harvest credentials, demonstrating a focus on long-term access and intelligence gathering. Their operations are likely aimed at gaining access to high-profile assets through indirect means.

Goals & Targeting

Judgement Panda's primary motivation appears to be espionage, targeting sectors that provide access to high-value assets such as government agencies, defense contractors, law firms, and MSPs. The choice of upstream providers indicates an interest in gaining access to their clients' networks, which may include more sensitive or high-profile targets. By focusing on these intermediaries, the group can potentially compromise a larger number of downstream victims with minimal direct exposure.

Enhanced Description

Judgement Panda operates with a specific focus on upstream service providers as a means to facilitate broader intrusions into their clients' networks. This approach suggests a strategic focus on achieving persistence and lateral movement within targeted environments, rather than direct attacks. The group's toolset includes spear-phishing campaigns that often employ Office documents or web-based mechanisms to deliver malicious payloads. Once initial access is achieved, Judgement Panda deploys URL web bugs and automated credential harvesting techniques to escalate privileges and expand their presence within the network. These activities align with common nation-state tactics of情报收集 and strategic maneuvering within adversarial networks.

Key Capabilities

  • Spear-phishing campaigns targeting upstream service providers
  • URL web bugs for persistent access and data exfiltration
  • Scheduled tasks automation for credential harvesting
  • Automated credential dumping techniques

MITRE ATT&CK Tactics

espionage
credential access
defense evasion

ATT&CK Techniques

T1059.003
T1078.001
T1543
T1217

Software / Tooling

Phishing kits (e.g., for Office document-based attacks)
Web-based malware (URL web bugs)

Campaigns & Victims

Judgement Panda's campaign patterns suggest a methodical approach, focusing on achieving long-term access rather than immediate damage or noise. Known campaigns involve targeting MSPs to gain indirect access to their clients. The group demonstrates patience and operational discipline, using automation for credential harvesting and persistence. Notable past operations include the compromise of multiple upstream providers as a stepping stone for further intrusions.

IOC Patterns

  • Spear-phishing emails with malicious Office attachments
  • URL web bugs hidden in legitimate-looking websites
  • Scheduled task creation on compromised systems
  • Automated credential harvesting via scripts

Recommended Actions

  • Implement network monitoring for unusual scheduled task activity and script executions.
  • Monitor for phishing attempts targeting MSPs and upstream providers.
  • Enforce multi-factor authentication (MFA) for sensitive accounts to mitigate credential theft.
  • Conduct regular audits of third-party service provider relationships to reduce exposure.

Suggested Tags

apt
espionage
nation-state
credential-theft

Confidence Assessment

Low confidence in specific targeting details and exact campaigns due to limited open-source intelligence. The described TTPs are logical for a nation-state actor, but the lack of detailed operational history leaves gaps in understanding their full capabilities and geographic targets.

ATT&CK Techniques

No techniques linked yet.

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

No IOCs linked yet.

References

No references recorded yet.

Intel Summary

0

Techniques

2

Tools

0

Campaigns

0

IOCs

0

Observed Data

0

Tactics

Tags

APT
Supply Chain Attack
Phishing
apt
espionage
nation-state
credential-theft

Details

Type
Nation-State
Resource Level
Government
Primary Motivation
Espionage
Country of Origin
China (CN)
Confidence
70%
Added
May 4, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.