DAGGER PANDA is a China-based nation-state cyber espionage group targeting government, military, and telecom sectors.
Analyst brief
DAGGER PANDA (also known as IceFog, Trident) is a China-based nation-state cyber espionage group active since at least 2011. The group primarily targets government institutions, military contractors, maritime and shipbuilding groups, and telecommunications operators in South Korea, the United States, Japan, and Germany. Their key TTPs include targeted spear-phishing and the deployment of custom backdoors like IceFog, maintaining communication with C2 servers. Defenders should focus on monitoring network traffic anomalies, enhancing email security, and scrutinizing connections to domains potentially associated with East Asian government entities.
DAGGER PANDA
IceFogTridentRedFoxtrot
nation-state
Operate since at least 2011, from several locations in China, with members in Korea and Japan as well. Possibly linked to Onion Dog. This threat actor targets government institutions, military contractors, maritime and shipbuilding groups, telecommunications operators, and others, primarily in Japan and South Korea.
origin (suspected)
🇨🇳China· state-sponsoredattribution confidence: medium (50)
What are the primary targeting sectors of DAGGER PANDA?+
DAGGER PANDA primarily targets government institutions, military contractors, maritime and shipbuilding groups, and telecommunications operators. Geographically, their main target countries are South Korea, the United States, Japan, and Germany.
What are the key TTPs used by DAGGER PANDA?+
The group's key TTPs include targeted spear-phishing campaigns and the deployment of custom backdoors, such as IceFog, which are used to maintain communication with C2 servers.