Liminal Panda
Liminal Panda is a China-nexus cyber espionage threat actor focused on telecommunications and related critical infrastructure. The actor is also tracked as CL-STA-0969 and Pepper Typhoon. Reporting cited in the content states that CL-STA-0969 heavily overlaps with activity CrowdStrike began tracking in 2024 as Liminal Panda, and Palo Alto Networks assessed the activity with high confidence as associated with a nation-state nexus and connected to Beijing. CrowdStrike assessed with low confidence that Liminal Panda had a connection to official Chinese hacking operations. The group is known for compromising telecom operator networks to collect subscriber information, call metadata, SMS messages, and location-related data, and has been described as having a deep understanding of mobile protocols. Victim sectors mentioned in the content include telecommunications organizations and telecom infrastructure in Southeast Asia, Southwest Asia, South Asia, Africa, Latin America, and the EU telecommunications sector; additional targeting mentioned includes government agencies and military entities in Latin America. Observed activity from February to November 2024 targeted mobile telecom networks in Southeast Asia and critical telecommunications infrastructure in Southwest Asia. Initial access was assessed as likely originating from SSH brute-force attacks using username and password dictionaries tailored for telecommunications equipment. The actor then deployed custom and public tooling, maintained persistent access, and emphasized stealth and operational security. Reported defense evasion and OPSEC measures included process-name masquerading, timestomping, DNS tunneling, routing traffic through compromised mobile operators, clearing authentication logs, and weakening or disabling SELinux by setting permissive mode. Tooling and malware associated in the content with CL-STA-0969/Liminal Panda include CordScan, NoDepDNS, AuthDoor, GTPDoor, EchoBackdoor, ChronosRAT (also called MystRodX), an SGSN emulator, Microsocks, FRP, FScan, and Responder. CordScan is described as a custom network scanning and packet-capture utility capable of capturing common mobile telecom communication protocols, including SGSN, and as being associated with collecting mobile location-related data. NoDepDNS tunnels communications over port 53. AuthDoor is described as a PAM backdoor that captures credentials and supports persistent access. GTPDoor tunnels command-and-control over GTP-C signaling. EchoBackdoor uses ICMP echo traffic for command execution. ChronosRAT/MystRodX is described as a modular Linux backdoor with AES-encrypted configuration and support for passive wake-up via crafted DNS or ICMP packets. The content also notes overlap with activity previously attributed to LightBasin, and states that as of October 2025 CrowdStrike updated its findings and attributed intrusions previously attributed to LightBasin to Liminal Panda instead. Related overlaps mentioned in the content include LightBasin, UNC1945, UNC2891, and UNC3886.
Know when an actor pivots toward your sector
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Tradecraft
23 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
Associated malware families
18 malware families attributed to this actor across reporting.
13 additional families tracked in Mallory.
Observables
23 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
Recent activity
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced as an example of a state-sponsored espionage group in the telecom surveillance landscape.
Telecom-focused espionage actor known for compromising telecom operator networks to collect subscriber information, call metadata, and SMS messages using customized signaling tools.
Targeting government agencies, telecom providers, and military entities in Latin America.
State-sponsored cluster targeting Southeast Asian telecommunications to enable remote control over compromised networks.
The version that knows your environment.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.