Deep Panda
Attribution profile
STIX characteristics
Threat actor characteristics are available to members.
Profile narrative
The threat actor known as Deep Panda, also referenced as APT 3 in public reporting, is identified as a China‑based group. The actors are Chinese nationals who reside in China and have been linked to the China‑based Internet security firm Guangzhou Bo Yu Information Technology Company Limited (Boyusec). This affiliation indicates that the group operates from within China and utilizes a corporate façade for its activities. The alias Deep Panda is used alongside the APT 3 designation in threat‑intelligence sources.
Targeting described in the indictment includes private corporations in the financial, engineering and technology sectors, with victims located in the United States and abroad. A separate report notes that the same group has directed spear‑phishing attacks at Hong Kong government agencies, indicating an interest in governmental targets within the region. The strategic objective behind the corporate intrusions is described as obtaining commercial advantage through the theft of trade secrets and sensitive internal documents. In contrast, the Hong Kong incidents were characterized as politically motivated espionage aimed at gathering intelligence on governmental operations. Both sets of targets demonstrate the actor’s ability to pursue differing objectives depending on the victim sector.
Regarding tactics, the Hong Kong campaign relied on spear‑phishing emails that contained malicious links and attachments delivering malware to compromise networks. The corporate intrusions alleged in the indictment involved maintaining unauthorized access to victim systems in order to exfiltrate confidential data, though specific malware families or toolsets are not detailed in the available sources. The group’s approach therefore combines social engineering for initial access with persistent internal movement to collect information. No public disclosures mention the use of zero‑day exploits, custom malware families, or particular toolkits beyond the generic malware delivered via phishing.
Attribution is firmly rooted in the actors’ Chinese nationality and their association with a China‑based company, supporting a China‑based origin for the operations. The publicly reported operations include a multi‑year campaign against three corporations across the financial, engineering and technology industries spanning from 2011 to May 2017. Another notable operation is the series of spear‑phishing attempts against Hong Kong government agencies in early August 2016, which led to the compromise of at least two government bodies. These examples illustrate the actor’s focus on both economic espionage and politically motivated intelligence gathering.
Incidents
Attributed incidents are available to members.
0 incidents