DIRECTORY

  • Alerts
  • APTs
  • Blog
  • Books
  • Certifications
  • Cheat Sheets
  • Courses
  • Cyber Briefing
  • CyberDecoded
  • CyberReview
  • CyberStory
  • CyberTips
  • Definitions
  • Domains
  • Entertainment
  • FAQ
  • Frameworks
  • Hardware Tools
  • Incidents
  • Malware
  • News
  • Papers
  • Podcasts
  • Quotes
  • Reports
  • Tools
  • Threats
  • Tutorials
No Result
View All Result
  • Login
  • Register
  • Cyber Citizens
  • Cyber Professionals
  • Institutions
CyberMaterial
Talk To An Expert
  • Cyber Citizens
  • Cyber Professionals
  • Institutions
CyberMaterial
No Result
View All Result
Talk To An Expert
CyberMaterial
Home APT

APT4 (Maverick Panda, Samurai Panda) – China

Reading Time: 3 mins read
in APT
Names APT4 (Mandiant), Maverick Panda (CrowdStrike), Wisp Team (Symantec), Sykipot Group (AlienVault)
Additional Names TG-0623 (SecureWorks), Bronze Edison (SecureWorks), Samurai Panda
Location China
Date of initial activity 2009
Suspected attribution China
Motivation Information theft and espionage
Associated tools GETKYS, LIFESAVER, CCHIP, SHYLILT, SWEETTOOTH, PHOTO, SOGO

Overview

APT4 appears to target the Defense Industrial Base (DIB) at a higher rate of frequency than other commercial organizations. However, APT4’s history of targeted intrusions is wide in scope. 

APT4 actors often leverage spear phishing messages using U.S. government, Department of Defense, or defense industrial base themes. APT4 actors may repurpose valid content from government or U.S. DoD web sites within their message bodies to lend them legitimacy.

Targets

Aerospace and Defense, Industrial Engineering, Electronics, Automotive, Government, Telecommunications, and Transportation. Target selection tends to focus on Asia Pacific victims in Japan, the Republic of Korea, and other democratic Asian victims.

Attack vectors

APT4 actors often leverage spear phishing messages using U.S. government, Department of Defense, or defense industrial base themes. APT4 actors may repurpose valid content from government or U.S. DoD web sites within their message bodies to lend them legitimacy.

How they work

The implant delivered by Samurai Panda uses a typical installation process whereby they:

  1. Leverage a spearphish with an exploit to get control of the execution flow of the targeted application. This file “drops” an XOR-encoded payload that unpacks itself and a configuration file.
  2. Next, the implant, which can perform in several different modes, typically will install itself as a service and then begin beaconing out to an adversary-controlled host.
  3. If that command-and-control host is online, the malicious service will download and instantiate a backdoor that provides remote access to the attacker, who will see the infected host’s identification information as well as the campaign code.

Indicators of Compromise (IOC)

  • IP addresses:
    • 176.34.146.10
    • 176.34.146.11
    • 176.34.146.12
    • 176.34.146.13
    • 176.34.146.14
  • Domain names:
    • a.apt4.biz
    • b.apt4.biz
    • c.apt4.biz
    • d.apt4.biz
    • e.apt4.biz
  • File hashes:
    • 5482598005525873334
    • 6682888614648030960
    • 7883188223870288576
    • 8183487833092546176
    • 8283787442314803776

References:

  • Who is Samurai Panda
  • APT4
  • APT4
Tags: Advanced Persistent ThreatAPTAPT4Bronze EdisonChinaMaverick PandaSamurai PandaSpear phishingSykipot GroupTG-0623Wisp Team
ADVERTISEMENT

Related Posts

APT43 (Kimsuky, Thallium) – North Korea

May 30, 2023

APT42 (TA453, Mint Sandstorm) – Iran

May 30, 2023
APT41 (WICKED PANDA, TG-2633) – China

APT41 (WICKED PANDA, TG-2633) – China

August 16, 2021
APT40 (Leviathan, BRONZE MOHAWK) – China

APT40 (Leviathan, BRONZE MOHAWK) – China

August 16, 2021

More Articles

Entertainment

Management Cast – Podcasts

February 13, 2023
Document

Selecting Secure Multi-factor Authentication Solutions

January 21, 2022
Alerts

Trellix Agent Vulnerabilities Addressed

April 5, 2023
Document

The Turning Point for IoT Security 2022

December 29, 2022
Incidents

Cyberattack closes more than 100 dental practices in Benelux

August 9, 2022
News

Outdated Directive Threatens Infrastructure

June 8, 2023
Incidents

2 Vendor Hacks Affect Nearly 1.5 Million and Counting

August 1, 2022
Quotes

“There has been a rash of…”

July 2, 2021
Load More

Security through data

Cybersecurity Domains

  • API Security
  • Business Continuity
  • Career Development
  • Compliance
  • Cryptography
  • HSM
  • KPIs / KRIs
  • Penetration Testing
  • Shift Left
  • Vulnerability Scan

Emerging Technologies

  • 5G
  • Artificial Intelligence
  • Blockchain
  • Cryptocurrency
  • Deepfake
  • E-Commerce
  • Healthcare
  • IoT
  • Quantum Computing

Frameworks

  • CIS Controls
  • CCPA
  • GDPR
  • NIST
  • 23 NYCRR 500
  • HIPAA

Repository

  • Books
  • Certifications
  • Definitions
  • Documents
  • Entertainment
  • Quotes
  • Reports

Threats

  • APTs
  • DDoS
  • Insider Threat
  • Malware
  • Phishing
  • Ransomware
  • Social Engineering

© 2023 | CyberMaterial | All rights reserved.

World’s #1 Cybersecurity Repository

  • About
  • Legal and Privacy Policy
  • Site Map
No Result
View All Result
  • Alerts
  • Incidents
  • News
  • Audience
    • Cyber Citizens
    • Cyber Professionals
    • Institutions
  • Highlights
    • Blog
    • CyberDecoded
    • Cyber Review
    • CyberStory
    • CyberTips
  • Cyber Risks
    • Alerts
    • Attackers
    • Domains
    • Incidents
    • Threats
  • Opportunities
    • Events
    • Jobs
  • Repository
    • Books
    • Certifications
    • Cheat Sheets
    • Courses
    • Definitions
    • Frameworks
    • Games
    • Hardware Tools
    • Memes
    • Movies
    • Papers
    • Podcasts
    • Quotes
    • Reports
    • Tutorials
  • Report Cyber Incident
  • GET HELP
  • Contact Us

Subscribe to our newsletter

© 2022 Cybermaterial - Security Through Data .

Welcome Back!

Sign In with Google
Sign In with Linked In
OR

Forgotten Password? Sign Up

Create New Account!

Sign Up with Google
Sign Up with Linked In
OR

All fields are required. Log In

Retrieve your password

Please enter your username or email address to reset your password.

Log In

Add New Playlist

This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy and Cookie Policy.