Adversary

Hammer Panda

ORIGIN

China

Community Identifiers

Temp.Zhenbao

Hammer Panda is a targeted intrusion adversary with a likely nexus to the first Technical Reconnaissance Bureau (TRB) of the Chinese People’s Liberation Army (PLA), located in the former Lanzhou Military Region (MR).

CrowdStrike Intelligence tracks Hammer Panda activity to at least 2013, during which time the adversary has used multiple unique and generic malware families including PlugX, NetTraveler, Saker, DarkSt, and ZeroT.

Historic Hammer Panda activity during the 2013-2014 timeframe has focused on India and related targets, while a shift in targeting at the end of 2014 into 2015 showed a clear focus on Russian-related issues. Hammer Panda operations generally focus on defense-related geopolitical issues which indicates primary targeting in the government and defense sectors; however Hammer Panda has been associated with limited targeting of financial firms as well..

Recent Activity:

The most recent Hammer Panda activity was identified by CrowdStrike Intelligence in December 2017, using the ZeroT malware family as part of a Russian-language themed attack. Reduced Hammer Panda activity throughout 2018-2020 may be due in part to widespread restructuring efforts begun in 2015 by the PLA, intended to reorganize Chinese-cyber forces unde the newly formed Strategic Support Force (SSF). These reorganization efforts have led to widely reduced operations from PLA associated adversary groups. CrowdStrike intelligence currently assesses Hammer Panda to be inactive.

Targeted Nations

  • Flag Icon of the country India

    India

  • Flag Icon of the country Russian Federation

    Russian Federation

  • Flag Icon of the country United States

    United States

  • Flag Icon of the country Uzbekistan

    Uzbekistan

Artwork

Adversary: Hammer Panda - Threat Actor

Crowdstrike Hammer Panda

I have read and accept the terms and conditions

Download
Explore Next Adversary

Terms and conditions

In order to download the adversary artwork, we kindly request you to accept our terms and conditions displayed below.

This image (“artwork”), is the intellectual property of CrowdStrike, Inc. and its affiliates and licensors (collectively, “us” or “we”) and may include other marks, trademarks, copyrighted materials, and other intellectual property (“assets”) that belong t o us, including, without limitation, CrowdStrike, the CrowdStrike logo, and CrowdStrike Falcon. We retain all right, title and interest in and to the artwork and all assets included therein. This artwork is offered to you as a convenience for your lawful a nd non-commercial use, solely as authorized by us, and subject to your compliance with these terms and conditions (“terms”) and any other guidelines or specifications that we may provide from time to time. We reserve the right to change these terms at any time without prior notice.

You should periodically check the latest information posted herein to be sure that you are in compliance. By downloading the artwork, you attest that you are at least 18 years of age and agree to the following terms, which const itute the sole and entire agreement between you and us with respect to the artwork. We reserve all rights not expressly granted to you herein. You may not use or display the artwork in any way: (i) that violates the rights of any person or entity or that may give rise to civil or criminal liability under laws or regulations applicable to you, another user, and/or CrowdStrike; (ii) that is defamatory, obscene, indecent, abusive, harassing, violent, hateful, inflammatory or otherwise objectionable; (iii) tha t is false, deceptive, misleading or fraudulent, including but not limited to: (a) any attempt to impersonate any person or entity, including any other user, CrowdStrike or a CrowdStrike employee; (b) any attempt to misrepresent your identity or affiliation with any person or organization; or (iv) for the purposes of recruiting, advertising, solicitation or commercial activities of any kind without our express written consent.

THE ARTWORK IS PROVIDED TO YOU BY CROWDSTRIKE ON AN “AS IS” AND “AS AVAILABLE” BA SIS, WITHOUT ANY WARRANTIES OF ANY KIND, EITHER EXPRESS OR IMPLIED. EXCEPT TO THE EXTENT THAT A DISCLAIMER OF LIABILITY IS PROHIBITED UNDER APPLICABLE LAW, IN NO EVENT WILL CROWDSTRIKE, ITS AFFILIATES AND ITS LICENSORS, EMPLOYEES, AGENTS, OFFICERS AND DIRE CTORS BE LIABLE FOR DAMAGES OF ANY KIND, UNDER ANY LEGAL THEORY, ARISING OUT OF OR IN CONNECTION WITH YOUR USE, OR INABILITY TO USE, THE ARTWORK.