Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors Vicious Panda

Also known as: SixLittleMonkeys

Description

Check Point Research discovered a new campaign against the Mongolian public sector, which takes advantage of the current Coronavirus scare, in order to deliver a previously unknown malware implant to the target. A closer look at this campaign allowed us to tie it to other operations which were carried out by the same anonymous group, dating back to at least 2016. Over the years, these operations targeted different sectors in multiple countries, such as Ukraine, Russia, and Belarus.

AI Analysis

· 1 week ago

Executive Summary

Vicious Panda, also known as SixLittleMonkeys, is a cyber threat actor targeting public sector entities in Mongolia and other regions, leveraging the COVID-19 pandemic to deliver novel malware. The group has been active since at least 2016, with operations spanning multiple countries including Ukraine, Russia, and Belarus. Their activities suggest a focus on state-sponsored or politically motivated cyber espionage.

Goals & Targeting

Vicious Panda appears to target sectors such as public administration and possibly other government-related entities, indicating a strategic focus on intelligence collection. Their geographic targeting of regions like Central Asia and Eastern Europe may be tied to political or economic interests. The group's campaigns are likely aimed at achieving long-term access to sensitive systems, consistent with espionage or disruption activities.

Enhanced Description

Vicious Panda is an advanced persistent threat (APT) group that has been operational since approximately 2016. The group's campaigns have targeted various sectors in multiple countries, including Ukraine, Russia, and Belarus, with recent activity focusing on the Mongolian public sector. Leveraging the global Coronavirus scare, Vicious Panda delivered a previously unknown malware implant to targets through sophisticated phishing campaigns. This indicates a high level of technical sophistication and an ability to adapt their tactics to current events. The group's targeting strategy suggests a focus on gathering intelligence from state-related institutions, aligning with potential espionage or geopolitical objectives.

Key Capabilities

  • Spear-phishing attacks with COVID-19 themed lures
  • Delivery of novel malware implants
  • Use of custom恶意软件 for persistence and data exfiltration
  • Long-term operational persistence across multiple campaigns

MITRE ATT&CK Tactics

Initial Access
Execution
Defense Evasion
Persistence

ATT&CK Techniques

T1059.003
T1055
T1003.001
T1566.001

Software / Tooling

Custom malware implants
Cobalt Strike (if inferred from TTPs)
Malicious email attachments (e.g., Office documents)

Campaigns & Victims

Vicious Panda's campaigns demonstrate a patient and methodical approach to compromising targets. Their use of COVID-themed phishing emails indicates an understanding of current events for weaponizing attacks. Notable operations include targeting Mongolian public sector entities in recent months, as well as earlier campaigns in Ukraine, Russia, and Belarus. The group's operational tempo appears deliberate, focusing on establishing long-term access rather than immediate exfiltration.

IOC Patterns

  • Spear-phishing emails with COVID-19 related lures
  • Malicious Microsoft Office documents delivered via email
  • C2 infrastructure using domain generation algorithms
  • Staging servers linked to known threat actor infrastructure

Recommended Actions

  • Implement email filtering and anti-phishing solutions
  • Train employees to recognize COVID-themed phishing attempts
  • Monitor for unusual network activity matching Vicious Panda's TTPs
  • Deploy endpoint detection and response (EDR) tools
  • Conduct regular threat hunting focused on APT indicators

Suggested Tags

APT
espionage
public sector
COVID-19 related threats
Central Asia
Eastern Europe

Confidence Assessment

Moderate confidence in Vicious Panda's operational details and targeting patterns, based largely on Check Point Research analysis. Additional data gaps include specific tools/malware details and the exact nature of their primary motivation beyond intelligence collection.

ATT&CK Techniques

No techniques linked yet.

Software / Tooling

No tools linked yet.

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

No IOCs linked yet.

References

No references recorded yet.

Intel Summary

0

Techniques

0

Tools

0

Campaigns

0

IOCs

0

Observed Data

0

Tactics

Tags

Backdoor / C2
Hacktivism
APT
espionage
public sector
COVID-19 related threats
Central Asia
Eastern Europe

Details

Type
Unknown
Country of Origin
C
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.