SABRE PANDA· China
SABRE PANDA is a China-originated espionage group known for targeting political and defense entities with spear-phishing attacks.
Analyst brief
“SABRE PANDA” is a China-originated threat actor typically engaged in espionage-oriented activities. It primarily targets political, diplomatic, and defense entities within the Asia-Pacific region. Its key TTPs involve purpose-built backdoor tools delivered through targeted spear-phishing emails, with web-based remote administration mechanisms for C2 communication. Defenders should enforce active monitoring for anomalous PowerShell execution, irregularities in web traffic, and suspicious domains in email origins.
FAQ2
What is the primary target profile of the SABRE PANDA threat actor?
SABRE PANDA primarily targets political, diplomatic, and defense entities within the Asia-Pacific region.
What defensive measures should be implemented to detect SABRE PANDA's activities?
Defenders should enforce active monitoring for anomalous PowerShell execution, irregularities in web traffic, and suspicious domains in email origins.
See also6
Every claim on this page is drawn from the cited source (MISP Galaxy, MITRE ATT&CK, ransomware.live) — no attribution is invented.