Threat Actor ๐จ๐ณ China
DAGGER PANDA
Also known as: IceFog ยท Trident ยท RedFoxtrot ยท Red Wendigo ยท PLA Unit 69010 ยท UAT-7290 ยท Red Foxtrot
Operate since at least 2011, from several locations in China, with members in Korea and Japan as well. Possibly linked to Onion Dog. This threat actor targets government institutions, military contractors, maritime and shipbuilding groups, telecommunications operators, and others, primarily in Japan and South Korea.
Indicators of Compromise 12
Domain 8[.]8[.]8[.]8 Filename .pkgdb Filename Bulbature Filename DriveSwitch Filename RushDrop Filename SilentRaid Filename busybox Filename chargen Filename daytime SHA-256 59568d0e2da98bad46f0e3165bcf8adadbf724d617ccebcfdaeafbb097b81596 SHA-256 723c1e59accbb781856a8407f1e64f36038e324d3f0bdb606d35c359ade08200 SHA-256 961ac6942c41c959be471bd7eea6e708f3222a8a607b51d59063d5c58c54a38d
MITRE ATT&CK TTPs 11
T1027 T1057 T1059.001 T1071.001 T1082 T1083 T1090 T1105 T1124 T1133 T1566
Obfuscated Files or Information
Defense Evasion
Process Discovery
Discovery
PowerShell
Execution
Web Protocols
Command And Control
System Information Discovery
Discovery
File and Directory Discovery
Discovery
Proxy
Command And Control
Ingress Tool Transfer
Command And Control
System Time Discovery
Discovery
External Remote Services
Persistence
Phishing
Initial Access