SYMBOLCOMMON_NAMEaka. SYNONYMS

JACKPOT PANDA  (Back to overview)


Jackpot Panda is a China-nexus state-sponsored APT primarily focused on cyber espionage against East and Southeast Asian entities, particularly in the online gambling sector and domestic security. They rapidly exploited CVE-2025-55182 using automated scanning, reconnaissance commands, and multi-vulnerability campaigns. Their activities have been linked to infrastructure associated with the exploitation of trojanized platforms and malware deployment, including SNOWLIGHT and VShell.


Associated Families

There are currently no families associated with this actor.


References
2025-12-19 ⋅ PolySwarm Tech Team ⋅ PolySwarm
Multiple Threat Actors Leveraging CVE-2025-55182 (React2Shell)
ANGRYREBEL COMPOOD MINOCAT Mirai SNOWLIGHT XMRIG EtherRAT Cobalt Strike Mirai VShell xmrig JACKPOT PANDA
2025-12-12 ⋅ Google ⋅ Aragorn Tseng, Austin Larsen, CASEY CHARRIER, Genevieve Stark, Robert Weiner, Zander Work
Multiple Threat Actors Exploit React2Shell (CVE-2025-55182)
ANGRYREBEL COMPOOD MINOCAT SNOWLIGHT Earth Lamia JACKPOT PANDA
2025-12-04 ⋅ Amazon ⋅ CJ Moses
China-nexus cyber threat groups rapidly exploit React2Shell vulnerability (CVE-2025-55182)
JACKPOT PANDA

Credits: MISP Project