TEMPER PANDA is a China-based APT group targeting government and political entities in Hong Kong, US, and Europe.
Analyst brief
TEMPER PANDA (also known as Admin338, MAGNESIUM) is a China-based state-sponsored cyber threat group. It primarily targets government, financial institutions, political parties, civil society, and pro-democracy activists in Hong Kong, the United States, and Europe. The group often uses Spearphishing Attachment (T1566.001) themed around current events for initial access, deploys RATs like PoisonIvy, BUBBLEWRAP, and LOWBALL, and performs discovery using built-in tools such as Systeminfo, Net, netstat, and ipconfig. Defenders should focus on scrutinizing email attachments, restricting macro execution, monitoring for unauthorized outbound C2 traffic, and detecting anomalous reconnaissance command executions.
TEMPER PANDA
Admin338Team338MAGNESIUM
nation-state
China-based cyber threat group. It has previously used newsworthy events as lures to deliver malware and has primarily targeted organizations involved in financial, economic, and trade policy, typically using publicly available RATs such as PoisonIvy, as well as some non-public backdoors. This threat actor targets prodemocratic activists and organizations in Hong Kong, European and international financial institutions, and a U.S.-based think tank.
origin (suspected)
🇨🇳China· state-sponsoredattribution confidence: medium (50)