Home / Companies / Crowdstrike / Blog / Post Details
Content Deep Dive

Business as Usual: Falcon Complete MDR Thwarts Novel VANGUARD PANDA (Volt Typhoon) Tradecraft

Blog post from Crowdstrike

Post Details
Company
Date Published
Author
Falcon Complete Team
Word Count
3,422
Company Posts That Month
15
Language
English
Hacker News Points
-
Post removed?
No
Summary

CrowdStrike's detailed investigation into the VANGUARD PANDA threat actor's activities highlights sophisticated cyber intrusions targeting U.S.-based critical infrastructure entities, leveraging vulnerabilities in ManageEngine Self-service Plus and Apache Tomcat to gain and maintain access. The threat actor employed a variety of techniques, including the use of webshells, living-off-the-land tactics, and backdoored Apache Tomcat libraries for persistent access, while also attempting to hinder forensic analysis by clearing logs and deleting artifacts. The investigation revealed that VANGUARD PANDA left behind generated Java source and compiled Class files, providing key evidence of their activities. CrowdStrike's Falcon Complete managed detection and response team, in collaboration with Falcon OverWatch and CrowdStrike Intelligence, successfully identified, contained, and remediated the intrusion, while offering actionable recommendations to prevent future incidents. The company emphasizes the importance of proactive threat hunting and collaboration between its teams to protect clients against advanced adversaries, highlighting its commitment to cybersecurity excellence.

Trends Found in this Post
Trend Post Mentions Total Month Mentions Posts Companies MoM
AI Agents 2 95 38 17 +67%
Zero Trust 2 308 58 16 +53%
AI Coding Assistant 1 240 38 16 -7%
AI Guardrails 1 121 44 18 +68%
Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.