Pandora

MITRE ATT&CK: S0664 View on attack.mitre.org

Aliases: Pandora

First seen
2020-01-01 00:00:00
Malware type
backdoor, rootkit
Family
Malware family
Operating systems
windows
Related IoCs
6 (4 malicious)
Last IoC activity
2026-08-31 09:35:05
Profile updated
2026-07-07 12:39:20

Targeted industries: government-and-public-sector technology-and-telecommunications

Targeted regions: country_code:cn country_code:us

Context

Pandora is a multistage kernel rootkit with backdoor functionality that has been in use by Threat Group-3390 since at least 2020.

Recent IoC activity

4 malicious indicators in Maltiverse are attributed to Pandora (S0664). The 4 most recently updated:

Detection coverage

  • 2 YARA rules
  • 382 Sigma rules

Malware & tools used

  • DLL (attack-pattern)
  • Symmetric Cryptography (attack-pattern)
  • Exploitation for Privilege Escalation (attack-pattern)
  • Windows Service (attack-pattern)
  • Web Protocols (attack-pattern)
  • Process Discovery (attack-pattern)
  • Traffic Signaling (attack-pattern)
  • Compression (attack-pattern)
  • Service Execution (attack-pattern)
  • Code Signing Policy Modification (attack-pattern)
  • Process Injection (attack-pattern)
  • Modify Registry (attack-pattern)
  • Ingress Tool Transfer (attack-pattern)

Used by threat actors

Detection rules

  • MALPEDIA_Win_Pandora_Auto (yara-rule)
  • DITEKSHEN_INDICATOR_TOOL_Pandora (yara-rule)

Reports & references

  • Trend Micro — Iron Tiger Apt Updates Toolkit With Evolved Sysupdate Malware Va (report)
  • Microsoft — Ransomware As A Service Understanding The Cybercrime Gig Economy And How To Protect Yourself (report)
  • secureworks.com — Bronze Starlight Ransomware Operations Use Hui Loader (report)
  • twitter.com — 1501857263493001217 (report)
  • dissectingmalwa.re — Pandora (report)
  • blog.cyble.com — Deep Dive Analysis Pandora Ransomware (report)
  • cloudsek.com — Technical Analysis Of Emerging Sophisticated Pandora Ransomware Group (report)
  • kienmanowar.wordpress.com — Quicknote Analysis Of Pandora Ransomware (report)
  • fortinet.com — Using Emulation Against Anti Reverse Engineering Techniques (report)
  • fortinet.com — Looking Inside Pandoras Box (report)
  • ransomlook.io — Pandora (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Pandora (report)
  • MITRE ATT&CK — S0664 (report)
  • rekings.com — Pandora Rat 2 2 (report)

External references