Glacial Panda is a China-linked cyberespionage threat actor tracked by CrowdStrike for long-running intrusions into telecommunications networks since at least 2018. The group primarily targets Linux, including legacy and unmanaged systems, at telecommunications operators in Asia and North America. Its objectives include obtaining sensitive call-detail records and communications telemetry; no confirmed evidence indicates that it has modified telecommunications protocols or directly intercepted communications. Glacial Panda gains access through exploitation of known vulnerabilities, weak passwords, and valid accounts. It has exploited Dirty COW (CVE-2016-5195) for root privilege escalation and attempted to use PwnKit (CVE-2021-4034). Following compromise, the actor conducts Unix/Linux host reconnaissance, uses SSH and netcat for remote access and lateral movement, and relies extensively on living-off-the-land techniques. For persistence, credential collection, and backdoor access, Glacial Panda deploys trojanized OpenSSH, SSHD, PAM, and cron components. CrowdStrike refers to this modified OpenSSH toolset as ShieldSlide. The implants capture authentication credentials and sessions, and a modified SSH server can enable backdoor authentication. The group has also installed reverse-shell backdoors and exfiltrated collected data through command-and-control channels.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
40 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 malware families attributed to this actor across reporting.
2 CVEs this actor has used in observed campaigns. 2 of them exploited in the wild.
In September 2018, GLACIAL PANDA exploited the DIRTYCOW vulnerability (CVE-2016-5195) to gain SSH authentication and escalate privileges to root on a targeted host.
Attack chains implemented by the threat actor make use of known security vulnerabilities or weak passwords aimed at internet-facing and unmanaged servers, with follow-on activities leveraging privilege escalation bugs like CVE-2016-5195 (aka Dirty COW) and CVE-2021-4034 (aka PwnKit).
23 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
China-linked espionage intrusions against telecommunications organizations to access and exfiltrate call detail records and communications telemetry; targets Linux/legacy telecom systems; uses vulnerability exploitation/weak passwords, privilege escalation, LotL, and trojanized OpenSSH for credential theft and backdoor access.
Glacial Panda is a China-linked group targeting the telecom sector, focusing on legacy Linux systems, deploying trojanized OpenSSH tools, and collecting authentication logs for lateral movement.
China-nexus endpoint-focused actor conducting long-dwell, stealthy intrusions for intelligence collection in telecommunications; targets Linux (including legacy) systems; deploys trojanized OpenSSH to log auth events and enable lateral movement via tracking remote connections (ShieldSlide).
Long-term cyberespionage operations using advanced custom malware implants.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.