IMPERSONATING PANDA· China
A threat actor likely linked to China, targeting government entities.
Analyst brief
IMPERSONATING PANDA is a threat actor of unknown origin, potentially linked to China. It primarily targets government entities and critical infrastructure. Its TTPs include spear-phishing, supply chain attacks, and custom C2 protocols. Defenders should watch for suspicious email attachments, monitor network traffic for data exfiltration attempts, and regularly check threat intelligence for indicators related to any identified C2 infrastructure.
FAQ2
Which sectors does IMPERSONATING PANDA primarily target?
IMPERSONATING PANDA primarily targets government entities and critical infrastructure.
What are the key TTPs used by IMPERSONATING PANDA?
Its TTPs include spear-phishing, supply chain attacks, and custom C2 protocols.
See also6
Every claim on this page is drawn from the cited source (MISP Galaxy, MITRE ATT&CK, ransomware.live) — no attribution is invented.