Operator Panda
Actor Type | Nation State |
---|---|
Attributed to Nation | China |
Directly Linked Intrusion Sets | Salt Typhoon , Earth Estries , GhostEmperor , FamousSparrow |
OPERATOR PANDA is an intrusion set tracked by CrowdStrike since November 2024 which shows overlap with the group known as Salt Typhoon (Microsoft).
The OPERATOR PANDA cyber threat group is assessed as a China-nexus adversary that has targeted telecoms and professional services sectors. The actor exploits internet-facing network appliances (such as Cisco switches) as part of their tradecraft. The group has been observed targeting US organizations.
Cyber Threat Graph Context
Explore how this Intrusion Set relates to the wider threat graph