Vicious Panda

Aliases: SixLittleMonkeys

First seen
2016-01-01 00:00:00
Origin
CN
Primary motivation
espionage
Sophistication
advanced
Resource level
government
Actor type
nation-state
Profile updated
2026-07-07 11:48:28

Targeted industries: government-and-public-sector

Targeted regions: country_code:mn country_code:ua country_code:ru country_code:by

Context

Check Point Research discovered a new campaign against the Mongolian public sector, which takes advantage of the current Coronavirus scare, in order to deliver a previously unknown malware implant to the target. A closer look at this campaign allowed us to tie it to other operations which were carried out by the same anonymous group, dating back to at least 2016. Over the years, these operations targeted different sectors in multiple countries, such as Ukraine, Russia, and Belarus.

Reports & references

  • ESET — Exchange Servers Under Siege 10 Apt Groups (report)
  • Kaspersky — 97353 (report)
  • Kaspersky — 82636 (report)
  • decoded.avast.io — Apt Group Planted Backdoors Targeting High Profile Networks In Central Asia (report)
  • ESET — Mikroceen Spying Backdoor High Profile Networks Central Asia (report)
  • research.checkpoint.com — Vicious Panda The Covid Campaign (report)
  • Palo Alto Unit 42 — Unit42 Threat Actors Target Government Belarus Using Cmstar Trojan (report)
  • media.kasperskycontenthub.com — Microcin Technical 4Pdf Eng Final S (report)
  • Kaspersky — 91897 (report)
  • Kaspersky — 97937 (report)
  • Kaspersky — 98230 (report)
  • Kaspersky — 104708 (report)

External references