LIMINAL PANDA is a China-nexus APT group known for harvesting mobile network intelligence via GSM protocols.
Analyst brief
LIMINAL PANDA is a China-nexus APT group primarily targeting telecommunications providers in southern Asia and Africa. The group uses custom malware and publicly available tools to achieve covert access, focusing heavily on SIGINT collection through GSM protocols to harvest subscriber information and call metadata. Defenders should focus on exploiting trust relationships between providers by monitoring for unauthorized access to core infrastructure and anomalous signaling traffic targeting mobile network data.
LIMINAL PANDA
unknown
LIMINAL PANDA is a China-nexus APT that targets telecommunications entities, employing custom malware and publicly available tools for covert access, C2, and data exfiltration. The adversary demonstrates extensive knowledge of telecom networks, utilizing GSM protocols to retrieve mobile subscriber information and call metadata. LIMINAL PANDA exploits trust relationships and security gaps between providers to access core infrastructure, indicating a focus on SIGINT collection rather than financial gain. Their intrusion activity has primarily affected telecom providers in southern Asia and Africa, with potential for broader targeting based on network configurations.
Which sector does LIMINAL PANDA target and what is its primary objective?+
LIMINAL PANDA primarily targets telecommunications providers in southern Asia and Africa. Their main objective is SIGINT collection by harvesting subscriber information and call metadata through GSM protocols.
What weakness does LIMINAL PANDA exploit to gain access between providers?+
The group exploits trust relationships and security gaps between providers to gain unauthorized access to core infrastructure.