I am Ironman: DEEP PANDA Uses Sakula Malware to Target Organizations in Multiple Sectors » Adversary Manifesto
ID: 0887f0fb-5274-4bfd-8215-ec77a5b815a3
STIX ID: report--0887f0fb-5274-4bfd-8215-ec77a5b815a3
Threat Score
85/100
Uploaded: 2026-08-07
Published Date: 2015-11-19
Last Modified Date: 2015-11-19
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
**Executive Summary:** CrowdStrike tracked a DEEP PANDA campaign (Apr–Sep 2014) that used malicious droppers masquerading as legitimate installers to deploy Sakula and Derusbi RATs via DLL side‑loading, signed with stolen certificates; victims included organizations in the U.S. defense industrial base, healthcare, government, and IT sectors, with observable C2 domains/IPs, spoofed login pages, and relationships to Scanbox activity.
