I am Ironman: DEEP PANDA Uses Sakula Malware to Target Organizations in Multiple Sectors » Adversary Manifesto
ID: 988768e8-a662-43cd-aaaa-16b0351f219b
STIX ID: report--988768e8-a662-43cd-aaaa-16b0351f219b
Threat Score
78/100
Uploaded: 2026-08-07
Published Date: 2015-02-05
Last Modified Date: 2015-02-05
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
CrowdStrike tracked a DEEP PANDA campaign (April–Sept 2014) that used trojanized installers and DLL side‑loading to deploy Sakula and Derusbi RATs, signed with stolen certificates (e.g., DTOPTOOLZ, Career Credit Co., Ltd.). Targets included U.S. defense industrial base, healthcare, government, and IT firms; C2 infrastructure and indicators (IP addresses, domains, file hashes, certificates) are provided, and links to Scanbox/SWC activity suggest broader adversary infrastructure reuse.
