Cisco Talos researchers have discovered that a hacking group using tools remote access has managed to obtain thousands of dollars in cryptocurrency, specifically Monero. The researchers call the group “Panda”. It does not use particularly sophisticated techniques, but it has been very active recently and mainly exploits vulnerable web applications. The tools used by hackersallow them to penetrate networks. The use of RATs puts organizations’ data at risk.
Hackers are exploiting exploits made public by Shadow Brokers, while also using the open-source application Mimikatz to obtain passwords.
Initially, the Panda group was linked to last year's MassMiner campaign. Then, it was linked to another mining campaign. Recently, the Panda group has greatly evolved its techniques and the exploits and payloads it uses.
According to researchers, hackers have attacked organizations in various sectors. Some of the targets include banks, healthcare services , telecommunications companies, and IT services
In July 2018, hackers exploited a WebLogic (CVE-2017-10271) to install a cryptominer related to MassMiner. They also massively scanned the internet for vulnerable servers and attempted to exploit an Apache Struts 2 vulnerability (CVE-2017-5638). They then used a PowerShell exploit to install the miner payload.

Talos estimates that the Panda team has amassed $100,000 worth of Monero.
It has also been found that the group has used the Gh0st RAT in its attacks.
In January 2019, hackers exploited a vulnerability in the ThinkPHP web framework (CNVD-2018-24942) to spread malware. In March, they used other exploits, but the tactics, techniques, and procedures were similar, so researchers realized that they were the same hackers.
The Panda team then used another payload, which exploited the Certutil tool in Windows to download the secondary payload.
Hackers have carried out many attacks during 2019 and have greatly evolved tools and techniques. Recently, they added a new set of domains to their list.
However, Panda doesn't take much care with security . Many of the old and new domains are hosted on the same IP address and their TTPs are similar across all their campaigns. Finally, their payloads are not very complex.
