CrowdStrike Intelligence tracks TURBINE PANDA in relation to attacks on a number of entities in the defense, aerospace, and manufacturing sectors primarily beginning in 2014. TURBINE PANDA heavily uses the PlugX RAT, popular among China-based targeted intrusion actors, often along with hyphenated C2 domains or domains that are meant to spoof targeted organizations. TURBINE PANDA operations appear...
Contact our team about
IOCs for this adversary