Vanguard Panda

China

Details

VANGUARD PANDA is a China-nexus targeted intrusion adversary that relies heavily on living-off-the-land (LOTL) techniques and also uses webshells in addition to well-known tools such as Impacket and Fast Reverse Proxy (FRP). Initial access methods have historically involved exploiting Zoho ManageEngine software and, likely more recently, Fortinet FortiGuard.  VANGUARD PANDA appears to focus on dat...

Community Identifiers

kHWdEU6ghaQvs3V

Objective

  • NSdcnueUfCpTg9oaW5mA0KL

Motivation

  • h4csE8mTZG3nJrN

Contact our team about
IOCs for this adversary

?

During a cybersecurity incident, indicators of compromise (IoC) are clues and evidence of a data breach.