Radio Panda

Threat Actor updated 7 months ago (2024-05-04T20:41:23.430Z)
Download STIX
Preview STIX
Radio Panda, also known as BlackTech, Palmerworm, Temp.Overboard, and Circuit Panda, is a state-sponsored Chinese Advanced Persistent Threat (APT) group that has been conducting cyber espionage attacks since at least 2010. This threat actor has targeted various sectors, including government, industrial, technology, media, electronics, telecommunication, and entities supporting the militaries of the U.S. and Japan. The group has been particularly active in exploiting routers, specifically those from Cisco Systems Inc., modifying their firmware to conceal its activities and establish persistence within the networks. In recent developments, U.S. and Japanese intelligence, law enforcement, and cybersecurity agencies have issued warnings about Radio Panda's malicious activities. In particular, they have highlighted the group's strategy of planting backdoors in Cisco router firmware to gain access to multinational companies' networks. This tactic allows the threat actor to pivot from smaller, international subsidiaries to the headquarters of affected organizations, replacing device firmware with its own malicious version. The NSA has underscored the severity of the threats from foreign intelligence, highlighting the active targeting and exploitation of routers by this alleged Chinese-linked hacking group. These actions demonstrate the decades-long pattern of intellectual property theft and exploitation by our adversaries, and there are concerns about their potential misuse of advances in AI. The persistent and advanced capabilities demonstrated by Radio Panda pose significant cybersecurity risks to both government entities and private sector organizations across multiple industries.
Description last updated: 2024-05-04T16:41:28.702Z
What's your take? (Question 1 of 2)
Help tune the shared Cybergeist dataset, assist your peers, and earn karma. Expand the panel to get started.
Possible Aliases / Cluster overlaps
It's hard to track cluster overlaps and naming conventions between vendors, so here are some possible overlapping names / profiles you also may want to look at. Create a free account to see the source evidence for each alias, and help fix any errors.
Alias DescriptionVotes
BlackTech is a possible alias for Radio Panda. BlackTech, a China-linked Advanced Persistent Threat (APT) group, poses a significant cybersecurity threat due to its sophisticated and covert hacking activities. As a threat actor, BlackTech's operations involve executing actions with malicious intent, which can be attributed to individuals, privat
4
Miscellaneous Associations
Other elements of context that could aid in the identification of relevance
Firmware
Apt
Analyst Notes & Discussion
Be the first to leave your mark here! Log in to share your views and vote.