logo

China's 'Liminal Panda' APT Attacks Telcos, Steals Phone Data

ID: b774769e-93a0-5a8d-9fb0-8a4a8c24a836

STIX ID: report--b774769e-93a0-5a8d-9fb0-8a4a8c24a836

Feed Name: Dark Reading

Threat Score
85/100

Date Published: 2024-11-20

Date Updated: 2026-04-21

Author: Nate Nelson, Contributing Writer

...
...

Liminal Panda is an advanced persistent threat, active since around 2020, that compromises telecom IT infrastructure across Asia and Africa to collect SMS, call records and device identifiers; the group uses techniques such as C2 infrastructure that emulates GSM, DNS-based hopping between providers, and traditional lateral movement to exfiltrate sensitive telecommunications metadata, and CrowdStrike links the activity to Chinese state intelligence objectives with low confidence.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.