Tue, 21-Oct-2025

Google Ads | Google Ads | Google Ads | Google Ads | Google Ads | Google Ads | Google Ads | Google Ads

China-linked Twisted Panda was discovered snooping on Russian defence research and development

China-linked Twisted Panda was discovered snooping on Russian defence research and development

According to Check Point Research, Chinese cyberspies targeted two Russian defense institutions and potentially another research site in Belarus.

According to the security firm, the latest effort, nicknamed Twisted Panda, is part of a broader, state-sponsored espionage operation that has been running for many months, if not almost a year.

The researchers outline the many harmful phases and payloads of the campaign, which leveraged sanctions-related phishing emails to target Russian organisations that are part of the state-owned defence giant Rostec Corporation, in a technical study.

Another Chinese advanced persistent threat (APT) group, Mustang Panda, was seen utilising the invasion of Ukraine to target Russian companies around the same time as the Twisted Panda operations, according to Check Point Research.

According to security specialists, Twisted Panda may have ties to Mustang Panda or another Beijing-backed surveillance ring known as Stone Panda, or APT10.

Other tools and tactics utilised in the latest campaign coincide with China-based APT organisations, they said, in addition to the timing of the assaults. The researchers ascribed the latest cyberspying operation “with high confidence to a Chinese threat actor” as a result of this.

During the investigation, the security firm discovered a comparable loader with what appeared to be a simpler variation of the same backdoor. Twisted Panda is expected to have been active since June 2021, according to the experts.