Unknown
Pacha Group
misp-galaxyrefreshed 2026-09-15
sigil
Analyst brief
Antd is a miner found in the wild on September 18, 2018. Recently we discovered that the authors from Antd are actively delivering newer campaigns deploying a broad number of components, most of them completely undetected and operating within compromised third party Linux servers. Furthermore, we have observed that some of the techniques implemented by this group are unconventional, and there is an element of sophistication to them.
We believe the authors behind this malware are from Chinese origin. GreedyAntd and classified the threat actor as Pacha Group.
Early access
Track Pacha Group on the wire.
Early access opens the actor API and MCP server first — and an alert every time this adversary lands on the wire. One email when it's ready.
bot-protected