Ethereal Panda

Actor Type Nation State
Attributed to Nation China
Directly Linked Intrusion Sets Flax Typhoon

ETHEREAL PANDA is a China based intrusion set tracked by CrowdStrike and with suspected overlap with Flax Typhoon (an intrusion set tracked by Microsoft) and RedJuliett (tracked by Recorded Future). According to researchers at CrowdStrike, the group has been observed targeting academic, technology and telecomms sectors, primarily in Taiwan.

In one incident, ETHEREAL PANDA was observed exploiting an Apache Tomcat instance for initial access before pivoting to an exposed SQL server and attempting to dump credentials using ProcDump and Mimikatz. The group deployed SoftEther VPN and Godzilla JSP webshells to support ongoing access to the victim environment.

Cyber Threat Graph Context

Explore how this Intrusion Set relates to the wider threat graph

References