Liminal Panda, also tracked as Pepper Typhoon, is a China-nexus advanced persistent threat group conducting cyberespionage against telecommunications networks since at least 2020. Its operations emphasize signals-intelligence collection, including subscriber identifiers, subscriber metadata, phone numbers, and call records. Targeting spans South Asia, Southeast Asia, and Africa. The activity cluster CL-STA-0969 substantially overlaps with Liminal Panda. Some telecommunications intrusions formerly attributed to LightBasin were subsequently reassigned to Liminal Panda; this reassignment does not establish equivalence between the groups or their associated clusters. The group demonstrates detailed knowledge of mobile-network infrastructure and exploits trust relationships between interconnected telecommunications providers. It compromises external DNS servers within GPRS networks, conducts SSH password-dictionary attacks against privileged accounts, and pivots between operators through trusted connectivity. It primarily targets Linux-based telecommunications infrastructure and has used modified BlueKeep exploits for lateral movement on Windows systems. ProxyChains, Microsocks, and Fast Reverse Proxy support tunneling and covert access. Its specialized toolkit includes CordScan for TCP, ICMP, GTP, and SCTP reconnaissance and subscriber-data collection; SIGTRANslator for telecommunications-protocol proxying and metadata interception; PingPong, an ICMP-triggered Linux reverse-shell backdoor; and TinyShell for persistent remote access. Overlapping CL-STA-0969 operations employ AuthDoor for credential capture and persistence, GTPDoor for signaling-based command-and-control, ChronosRAT, and the DNS-tunneling backdoor NoDepDNS. Operational-security techniques include process masquerading, timestomping, authentication-log removal, weakening SELinux controls, and firewall-rule modifications to preserve redundant access. Telecommunications-specific protocols and compromised operator infrastructure help conceal reconnaissance, command-and-control, and collection activity within trusted network traffic.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Attributed origin per open-source reporting.
37 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
22 malware families attributed to this actor across reporting.
17 additional families tracked in Mallory.
1 CVE this actor has used in observed campaigns. 1 of them exploited in the wild.
24 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Mentioned as historical context for TinyShell usage against telecommunications networks and edge devices, not as an attributed operator of the newly reported implants.
Mentioned as a China-nexus cluster previously associated with TinyShell and targeting telecommunications networks and edge devices. The article does not attribute the current campaign to this group.
Referenced as an example of a state-sponsored espionage group in the telecom surveillance landscape.
Telecom-focused espionage actor known for compromising telecom operator networks to collect subscriber information, call metadata, and SMS messages using customized signaling tools.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.