JACKPOT PANDA is a China-nexus state-sponsored APT group known for rapid vulnerability exploitation targeting the online gambling sector.
Analyst brief
JACKPOT PANDA is a China-nexus state-sponsored APT group. Its primary targets are entities in the online gambling sector and domestic security within East and Southeast Asia. The actor is characterized by rapid exploitation of vulnerabilities like CVE-2025-55182 through automated scanning and employs tools such as SNOWLIGHT and VShell deployed via trojanized platforms. Defenders should prioritize patching for CVE-2025-55182, monitor for suspicious scanning activity, and implement detections for the associated SNOWLIGHT and VShell IoCs.
JACKPOT PANDA
unknown
Jackpot Panda is a China-nexus state-sponsored APT primarily focused on cyber espionage against East and Southeast Asian entities, particularly in the online gambling sector and domestic security. They rapidly exploited CVE-2025-55182 using automated scanning, reconnaissance commands, and multi-vulnerability campaigns. Their activities have been linked to infrastructure associated with the exploitation of trojanized platforms and malware deployment, including SNOWLIGHT and VShell.