SharpPanda (Sharp Dragon) is a China-based APT group targeting Germany via spear-phishing and old Office exploits.
Analyst brief
SharpPanda, also tracked as Sharp Dragon, is a China-based APT group active since at least 2018. The group primarily targets entities in Germany, leveraging spear-phishing campaigns for initial access. Their key TTPs involve exploiting outdated Microsoft Office document vulnerabilities, deploying novel evasion techniques, and utilizing highly potent backdoor malware. Defenders should focus on anti-spear-phishing training, monitor Office document macros, and enhance detection of anomalous process behavior.
SharpPanda
Sharp Dragon
unknown
SharpPanda, an APT group originating from China, has seen a rise in its cyber-attack operations starting from at least 2018. The APT group utilizes spear-phishing techniques to obtain initial access, employing a combination of outdated Microsoft Office document vulnerabilities, novel evasion techniques, and highly potent backdoor malware.