Wicked Panda
Attributed to Nation | China |
---|---|
Directly Linked Intrusion Sets | Wicked Spider , APT41 |
Affiliated Intrusion Sets | Winnti |
Associated Threat Actor | Chengdu 404 |
Associated MITRE ATT&CK Group | APT41 (G0096) |
WICKED PANDA is an intrusion set tracked by researchers at CrowdStrike who they identify as 'one of the most prolific and effective China-based adversaries from the mid 2010s into the 2020s'. The groups objectives reportedly often align with Chinese Communist Party objectives.
The group shows overlap with other tracked intrusion sets attributed to China, such as APT41 and wider Winnti activity. The actors behind WICKED PANDA intrusions have also been observed by CrowdStrike analysts taking part in financially motivated activity which they track under a different moniker 'WICKED SPIDER'.
WICKED PANDA has been observed targeting multiple sectors including hospitality, technology, telecommunications and gaming. The group uses 'living-off-the-land' techniques such as downloading firewalls with Windows' Background Intelligence Transfer Service (BITS). The group also deploys a variety of malware and custom tooling.
Cyber Threat Graph Context
Explore how this Intrusion Set relates to the wider threat graph