Asnarök

Aliases: Personal Panda

First seen
2020-04-01 00:00:00
Primary motivation
financial-gain
Sophistication
innovator
Resource level
organization
Actor type
criminal
Profile updated
2026-07-07 12:18:15

Targeted industries: technology-and-telecommunications financial-services government-and-public-sector

Context

Asnarök is a threat actor that exploited CVE-2020-12271 and utilized command injection privilege escalation to gain root access to devices and install the Asnarök Trojan and demonstrated significant changes in TTPs, including the deployment of a web shell that did not reach out to external C2 for commands. X-Ops identified a patient-zero device linked to the attack and observed the use of an IC.sh script that stole local user account data. The actor's activities were linked to a broader pattern of malicious exploit research and targeted vulnerabilities disclosed by bug bounty researchers.

Exploited vulnerabilities

  • CVE-2020-12271 (vulnerability)

Reports & references

  • news.sophos.com — Pacific Rim Neutralizing China Based Threat (report)
  • news.sophos.com — Pacific Rim Timeline (report)

External references