logo

Hunting Pandas

ID: efac2ff3-3fcc-52a3-8ac5-39a9828adbc5

STIX ID: report--efac2ff3-3fcc-52a3-8ac5-39a9828adbc5

Feed Name: IntelInsights (Substack)

Threat Score
70/100

Date Published: 2025-04-04

Date Updated: 2026-04-19

Author: Vasilis Orlof

...
...

This report investigates infrastructure associated with Mustang Panda/Red Delta, pivoting from an external malware analysis to identify related domains, IPs, header/banner hashes, and JARM fingerprints, with patterns across specific ASNs. The analysis surfaces additional infrastructure, connects findings to PlugX activity, and notes potential operational overlap with APT41, culminating in a consolidated IoC set with confidence levels for hunting and detection.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.