Asnarök
Aliases: Personal Panda
- First seen
- 2020-04-01 00:00:00
- Primary motivation
- financial-gain
- Sophistication
- innovator
- Resource level
- organization
- Actor type
- criminal
- Profile updated
- 2026-07-07 12:18:15
Targeted industries: technology-and-telecommunications financial-services government-and-public-sector
Context
Asnarök is a threat actor that exploited CVE-2020-12271 and utilized command injection privilege escalation to gain root access to devices and install the Asnarök Trojan and demonstrated significant changes in TTPs, including the deployment of a web shell that did not reach out to external C2 for commands. X-Ops identified a patient-zero device linked to the attack and observed the use of an IC.sh script that stole local user account data. The actor's activities were linked to a broader pattern of malicious exploit research and targeted vulnerabilities disclosed by bug bounty researchers.
Exploited vulnerabilities
- CVE-2020-12271 (vulnerability)
Reports & references
- news.sophos.com — Pacific Rim Neutralizing China Based Threat (report)
- news.sophos.com — Pacific Rim Timeline (report)