ELECTRIC PANDA· China
A suspected Chinese-origin actor known for intellectual property theft using spear-phishing and DNS tunneling.
Analyst brief
ELECTRIC PANDA is a cyber threat actor of suspected Chinese origin with an undetermined classification. It primarily targets the technology, financial, and government sectors for intellectual property theft. Common TTPs include targeted spear-phishing with politically themed lures for initial access, and custom PowerShell scripts combined with DNS tunneling for C2 and lateral movement. Defenders should prioritize monitoring for anomalous PowerShell execution, unusual DNS query patterns, and data exfiltration to foreign IP addresses.
FAQ2
What sectors does ELECTRIC PANDA target?
ELECTRIC PANDA primarily targets the technology, financial, and government sectors.
What network activities should be monitored to defend against ELECTRIC PANDA?
Defenders should monitor for anomalous PowerShell execution, unusual DNS query patterns, and data exfiltration to foreign IP addresses.
See also6
Every claim on this page is drawn from the cited source (MISP Galaxy, MITRE ATT&CK, ransomware.live) — no attribution is invented.