A threat actor active since 2008 targeting governments in Taiwan and Malaysia by hiding encrypted payloads in registry keys.
Analyst brief
ShaggyPanther is a threat actor active since 2008 that primarily targets government entities in Taiwan and Malaysia. Their activities have also been detected in Indonesia and Syria, though their exact origin remains unknown. They rely on the TTP of hiding encrypted payloads within registry keys. Defenders should focus monitoring on unusual registry modifications and suspicious encrypted data blobs.
ShaggyPanther
unknown
ShaggyPanther is a threat actor that primarily targets government entities in Taiwan and Malaysia. They have been active since 2008 and utilize hidden encrypted payloads in registry keys. Their activities have been detected in various locations, including Indonesia and Syria.