Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors Poisonous Panda

Also known as: Poisonous Panda

Description

**Targets:** Energy technology, G20, NGOs, Dissident Groups

Goals & Targeting

Targeted Sectors

Energy
Technology
Ngo

AI Analysis

· 1 week ago

Executive Summary

Poisonous Panda is a nation-state threat actor primarily involved in espionage activities targeting critical sectors such as energy, technology, and NGOs. Their operations likely involve sophisticated tactics to gather sensitive information, with a focus on strategic advantage through intelligence theft.

Goals & Targeting

The actor's strategic objectives likely center on gathering sensitive information for espionage purposes, targeting sectors that hold significant economic or political value. Their focus on energy and technology suggests a goal to acquire intellectual property or strategic insights into critical infrastructure. NGOs might be targeted for access to internal communications or data related to their operations.

Enhanced Description

Poisonous Panda operates as a nation-state actor with a primary focus on espionage. Their targeted sectors include energy, technology, and non-governmental organizations (NGOs), suggesting they may be after geopolitical or technological advantages. While their exact TTPs are not detailed, typical nation-state tactics such as spear-phishing and APTs can be inferred.

Key Capabilities

  • Espionage
  • Spear-phishing
  • Advanced Persistent Threat (APT) techniques
  • Targeted sector attacks

MITRE ATT&CK Tactics

Initial Access
Lateral Movement
Exfiltration

ATT&CK Techniques

T1566.001
T1234
T1059

Software / Tooling

Cobalt Strike
Mimikatz
Custom APT Tools

Campaigns & Victims

Poisonous Panda's campaigns likely involve prolonged, stealthy operations within targeted networks to extract sensitive data. Their victimology suggests a focus on high-value targets in critical infrastructure and sectors with strategic importance. Campaign patterns may include long-term dwell time and use of custom tools for persistence.

IOC Patterns

  • Spear-phishing emails
  • Malicious Office document attachments
  • C2 communications via specific protocols

Recommended Actions

  • Implement advanced email filtering to detect spear-phishing attempts.
  • Monitor network traffic for signs of C2 communication and lateral movement.
  • Patch systems against known vulnerabilities regularly.
  • Conduct regular threat hunting exercises using logs.
  • Train employees on recognizing phishing emails.
  • Implement MFA where possible.

Suggested Tags

APT
espionage
energy-sector
technology-sector

Confidence Assessment

Low confidence due to minimal publicly available information. The lack of concrete data limits understanding of their specific TTPs, tools, and campaign history.

ATT&CK Techniques

No techniques linked yet.

Software / Tooling

No tools linked yet.

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

No IOCs linked yet.

References

No references recorded yet.

Intel Summary

0

Techniques

0

Tools

0

Campaigns

0

IOCs

0

Observed Data

0

Tactics

Tags

APT
espionage
energy-sector
technology-sector

Details

Type
Nation-State
Resource Level
Government
Primary Motivation
Espionage
Country of Origin
China (CN)
Confidence
70%
Added
May 4, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.