Home/Threat Actor/Vanguard Panda
Threat Actor

Vanguard Panda

vanguard_panda · china · active since 2020-01

Vanguard Panda (CrowdStrike canonical designation, May 2023 first-disclosure) is a China-aligned cyber espionage cluster tracked by CrowdStrike with significant operational overlap with Microsoft-tracked Volt Typhoon (volt_typhoon.yaml), temporally adjacent May 2023 disclosures created analytical cluster-identity question (operationally-identical with different vendor designations vs. operationally-overlapping with shared operator-network origin vs. operationally- distinct within same broader sub-ecosystem) that remains partially open in public reporting.

signature operational mission is US critical infrastructure preposition targeting (communications, utility, manufacturing, transportation, maritime sectors) for persistent foothold establishment operationally positioning cluster for potential follow-on operations during US-China geopolitical tension.

Living Off The Land (LOLBin) operational pattern using legitimate Windows administrative tools (PowerShell, WMI, ntdsutil, comsvcs.dll abuse), compromised home/SOHO router infrastructure for multi-hop proxy C2 (KV-Botnet of end-of-life Cisco and NetGear routers FBI-disrupted January 2024), and operational discipline consistent with long- dwell preposition operations.

operationally ecosystem- adjacent to but distinct from Volt Typhoon, Salt Typhoon, Silk Typhoon, Flax Typhoon, Storm-0558, Earth Estries, TAG-100, Velvet Ant, UNC4191, and the APT* clusters all curated separately in this corpus.

china confidence: high 6 aliases MITRE ATT&CK G1017 ↗

Profile

Vanguard Panda (CrowdStrike canonical designation, May 2023 first-disclosure) is a China-aligned cyber espionage cluster canonically tracked by CrowdStrike with significant operational overlap with the Microsoft-tracked Volt Typhoon cluster (curated separately at volt_typhoon.yaml). The temporally adjacent CrowdStrike Vanguard Panda and Microsoft Volt Typhoon disclosures in May 2023 created an analytical cluster-identity question that remains partially open in public reporting and represents one of the most operationally- significant cluster-identity questions in the Chinese- aligned cluster ecosystem. The cluster's operational distinctiveness is the US critical infrastructure preposition operational mission, targeting US critical infrastructure organizations (communications, utility, manufacturing, transportation, construction, maritime, government, IT, education sectors) for persistent foothold establishment that operationally positions the cluster for potential follow-on operations including operational disruption during periods of US-China geopolitical tension. The operational mission is operationally distinct from conventional espionage operations focused on intelligence collection and is consistent with documented Chinese state strategic priorities for preposition capabilities against US critical infrastructure. Operational tradecraft includes the Living Off The Land (LOLBin) operational pattern, extensive use of legitimate Windows administrative tools (PowerShell, WMI, ntdsutil, wmic, comsvcs.dll) for operational activities to minimize custom-malware detection visibility.

compromised home/SOHO router infrastructure for multi-hop proxy command-and- control (including the KV-Botnet of compromised end-of-life Cisco and NetGear routers disrupted by FBI operation January 2024)

extensive credential harvesting via comsvcs.dll abuse and adjacent LOLBin tradecraft.

perimeter- appliance N-day exploitation for initial access.

and operational discipline consistent with long-dwell preposition operations. The Vanguard Panda / Volt Typhoon analytical cluster- identity question is operationally similar to other dual- tracking patterns observed across the broader threat- intelligence vendor ecosystem, Earth Estries / Salt Typhoon analytical adjacency (earth_estries.yaml), TAG-110 / UAC-0063 dual-tracking (tag_110.yaml), and selectively additional dual-tracking patterns. Industry analysts have not consistently treated Vanguard Panda and Volt Typhoon as operationally-identical, both designations continue to receive distinct tracking, and analytical uncertainty about the exact relationship persists in public reporting. Vanguard Panda is curated as a distinct entry from Volt Typhoon based on the distinct CrowdStrike vendor tracking and the partial-overlap-but-not-confirmed-identical analytical positioning. The cluster is operationally ecosystem-adjacent to all other Chinese-aligned clusters curated separately in this corpus.

Aliases

6
vanguard_pandavanguard pandavolt_typhoon_overlap_vanguard_pandachina-aligned-critical-infrastructure-preposition-clusterus-critical-infrastructure-china-cluster-2023vanguardpanda

MITRE ATT&CK aliases

7
Additional names MITRE lists for G1017.
Volt TyphoonBRONZE SILHOUETTEDEV-0391UNC3236VoltziteInsidious TaurusDazedToad

Notable Campaigns

3
2024KV-Botnet FBI Disruption Operational Context (January 2024)
2023-2025Volt Typhoon Cluster-Overlap Analytical Question
2023CrowdStrike Vanguard Panda Canonical Public Disclosure (May 2023)

Attribution & Reporting

Attributed by
CrowdStrikeMicrosoft Threat Intelligence (adjacent Volt Typhoon tracking)Mandiant (Google Threat Intelligence)SentinelOneRecorded FutureCISA (US Cybersecurity and Infrastructure Security Agency)NSA (National Security Agency)FBI (Federal Bureau of Investigation)UK National Cyber Security Centre (NCSC)Australian Cyber Security Centre (ACSC)Canadian Centre for Cyber Security (CCCS)New Zealand National Cyber Security Centre (NCSC-NZ)
Key reporting
reportCrowdStrike: Falcon Complete Thwarts Vanguard Panda Tradecraft (May 2023), canonical first-disclosure
reportMicrosoft Threat Intelligence: Volt Typhoon (May 24, 2023), adjacent / overlapping cluster disclosure
reportCISA / NSA / FBI Joint Cybersecurity Advisory: People's Republic of China State-Sponsored Cyber Actor Living Off the Land (AA23-144A)
reportFive Eyes Joint Advisory: Volt Typhoon Critical Infrastructure Targeting
reportUS DOJ: US Government Disrupts Botnet PRC Used to Conceal Hacking US Critical Infrastructure (January 2024)
reportMalpedia Actor Profile: Vanguard Panda

Operational

State sponsor

China-aligned cyber espionage cluster canonically tracked by CrowdStrike (Vanguard Panda designation) with significant operational overlap with the Microsoft-tracked Volt Typhoon cluster (curated separately at volt_typhoon.yaml). CrowdStrike publicly disclosed Vanguard Panda in May 2023, temporally adjacent to Microsoft's May 24, 2023 canonical disclosure of Volt Typhoon, with both vendor disclosures describing operationally-similar China-aligned clusters targeting US critical infrastructure for persistent foothold (preposition) operations. The CrowdStrike Vanguard Panda disclosure and Microsoft Volt Typhoon disclosure created an analytical cluster-identity question, whether Vanguard Panda and Volt Typhoon represent operationally-identical clusters tracked under distinct vendor designations, operationally-overlapping clusters with shared operator-network origin and substantial tradecraft / infrastructure overlap, or operationally-distinct clusters within the same broader Chinese-aligned critical- infrastructure-targeting sub-ecosystem.

The analytical question remains partially open in public reporting and represents one of the most operationally-significant cluster- identity questions in the Chinese-aligned cluster ecosystem. CrowdStrike's attribution is based on operational tradecraft consistent with Chinese state-aligned cyber espionage operations, targeting profile (US critical infrastructure sectors, communications, manufacturing, utility, transportation, construction, maritime, government, IT, education, consistent with Chinese state intelligence priorities for understanding and pre-positioning against US critical infrastructure), tooling overlap with broader Chinese-aligned cluster ecosystem, infrastructure analysis, and operational tradecraft elements consistent with PRC state-aligned operations. The cluster has not been formally attributed by any government cybersecurity authority to a specific Chinese government agency, military unit (PLA SSF), or intelligence service (MSS).

Vanguard Panda is curated as a distinct entry from Volt Typhoon based on the distinct CrowdStrike vendor tracking and the partial-overlap-but-not-confirmed-identical analytical positioning.

Motivations
cyber_espionage, critical_infrastructure_preposition_operations, us_critical_infrastructure_intelligence_collection, chinese_state_strategic_preposition_priorities, persistent_living_off_the_land_operations
Sectors
Regions

Detection Blind Spots

60 techniques
Across this actor’s 60 mapped techniques, the share covered by each detection layer. Low bars are where you’d be blind if this actor targeted you.
Behavioral / log (Sigma)58/60 · 96%
Analytics (MITRE CAR)39/60 · 65%
Runtime / container (Falco)11/60 · 18%
File / malware (YARA)1/60 · 1%
Network (Suricata/Snort)16/60 · 26%
Vuln scan (Nuclei)0/60 · 0%

Atomic Test Plan

30 techniques
Runnable Atomic Red Team tests covering this actor’s mapped techniques - validate your detections against this specific adversary. Cross-reference the blind spots above. For authorized lab / purple-team use. Open the full builder
Intelligence Graph · click any node to traverse
CVETechnique ActorTool Family
drag to reposition · click any node to traverse · button top-right enlarges
External lookups - second-class, for what we don’t hold ourselves
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh  ·  Open-source threat intelligence platform  ·  100+ authoritative sources  ·  Every fact traces to its origin