GOBLIN PANDA

⚠️ Critical
Also known as: Conimes, Cycldek, GOBLIN PANDA, Conimes Team, China1937CN Team, Temp.Conimes, Earth Zhulong, Goblin Panda

Goblin Panda is one of a handful of elite Chinese advanced persistent threat (APT) groups. Most Chinese APTs target the United States and NATO, but Goblin Panda focuses primarily on Southeast Asia.

🌍 Country China
Risk Level Critical
Private Sector

Introduction

Goblin Panda is one of a handful of elite Chinese advanced persistent threat (APT) groups. Most Chinese APTs target the United States and NATO, but Goblin Panda focuses primarily on Southeast Asia.

Activities and Tactics

Targeted Sectors: Private Sector

Country of Origin: 🇨🇳 China

Risk Level: Critical

Suspected Victims: Malaysia, India, Indonesia, Japan, Philippines, Southeast Asia, South Korea, Vietnam

Notable Campaigns

Information pending cataloguing.

Tactics, Techniques, and Procedures (TTPs)

Information pending cataloguing.

Notable Indicators of Compromise (IOCs)

No curated IOCs are currently published for this actor. This section will be updated when stable, attributable indicators are available.

Malware and Tools

  • UNITEDRAKE
  • ZeGhost:
  • PlugX:
  • tempfun:
  • NewCore RAT:
  • Sisfader:
  • RoyalRoad RTF Weaponizer:
  • BlueCore:
  • RedCore:

Attribution and Evidence

Country of Origin: China Additional attribution information pending cataloguing.

References

References pending cataloguing.