ctipilot.ch

VAULT PANDA

actor · actor:vault-panda

China-nexus adversary tracked by CrowdStrike, named in the 2026 Threat Hunting Report as having launched deliberate attacks within 24 hours of the public disclosure of a critical web-application vulnerability during H1 2026 (CrowdStrike Counter Adversary Operations, 2026-08-03).

Coverage timeline
1
first 2026-08-04 → last 2026-08-04
Peak priority
notable
1 notable
Sources cited
2
2 hosts
Sections touched
1
research
Co-occurring entities
0
no co-occurrence
ATT&CK techniques
4
pinned v19.1 · see below

ATT&CK techniques

4 techniques observed across 1 entry — derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.1 · compare on the matrix · Navigator layer (JSON)

Initial Access TA0001

T1078.004Valid Accounts: Cloud Accounts×1

Valid accounts in cloud environments may allow adversaries to perform actions to achieve Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Cloud accounts are those created and configured by an organization for use by users, remote support, services, or for administration of resources within a cloud service provider or SaaS application. Cloud Accounts can exist solely in the cloud; alternatively, they may be hybrid-joined between on-premises systems and the cloud through syncing or federation with other identity sources such as Windows Active Directory.

Evidence: 2026-08-04/crowdstrike-2026-threat-hunting-report-exploitation-window · ATT&CK page ↗

T1190Exploit Public-Facing Application×1

Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network. The weakness in the system can be a software bug, a temporary glitch, or a misconfiguration.

Evidence: 2026-08-04/crowdstrike-2026-threat-hunting-report-exploitation-window · ATT&CK page ↗

T1195.002Supply Chain Compromise: Compromise Software Supply Chain×1

Adversaries may manipulate application software prior to receipt by a final consumer for the purpose of data or system compromise. Supply chain compromise of software can take place in a number of ways, including manipulation of the application source code, manipulation of the update/distribution mechanism for that software, or replacing compiled releases with a modified version.

Evidence: 2026-08-04/crowdstrike-2026-threat-hunting-report-exploitation-window · ATT&CK page ↗

T1566.004Phishing: Spearphishing Voice×1

Adversaries may use voice communications to ultimately gain access to victim systems. Spearphishing voice is a specific variant of spearphishing. It is different from other forms of spearphishing in that it employs the use of manipulating a user into providing access to systems through a phone call or other forms of voice communications. Spearphishing frequently involves social engineering techniques, such as posing as a trusted source (ex: Impersonation) and/or creating a sense of urgency or alarm for the recipient.

Evidence: 2026-08-04/crowdstrike-2026-threat-hunting-report-exploitation-window · ATT&CK page ↗

Persistence TA0003

T1078.004Valid Accounts: Cloud Accounts×1

Valid accounts in cloud environments may allow adversaries to perform actions to achieve Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Cloud accounts are those created and configured by an organization for use by users, remote support, services, or for administration of resources within a cloud service provider or SaaS application. Cloud Accounts can exist solely in the cloud; alternatively, they may be hybrid-joined between on-premises systems and the cloud through syncing or federation with other identity sources such as Windows Active Directory.

Evidence: 2026-08-04/crowdstrike-2026-threat-hunting-report-exploitation-window · ATT&CK page ↗

Privilege Escalation TA0004

T1078.004Valid Accounts: Cloud Accounts×1

Valid accounts in cloud environments may allow adversaries to perform actions to achieve Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Cloud accounts are those created and configured by an organization for use by users, remote support, services, or for administration of resources within a cloud service provider or SaaS application. Cloud Accounts can exist solely in the cloud; alternatively, they may be hybrid-joined between on-premises systems and the cloud through syncing or federation with other identity sources such as Windows Active Directory.

Evidence: 2026-08-04/crowdstrike-2026-threat-hunting-report-exploitation-window · ATT&CK page ↗

Stealth TA0005

T1078.004Valid Accounts: Cloud Accounts×1

Valid accounts in cloud environments may allow adversaries to perform actions to achieve Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Cloud accounts are those created and configured by an organization for use by users, remote support, services, or for administration of resources within a cloud service provider or SaaS application. Cloud Accounts can exist solely in the cloud; alternatively, they may be hybrid-joined between on-premises systems and the cloud through syncing or federation with other identity sources such as Windows Active Directory.

Evidence: 2026-08-04/crowdstrike-2026-threat-hunting-report-exploitation-window · ATT&CK page ↗

Story timeline

  1. 2026-08-04CrowdStrike 2026 Threat Hunting Report: 88% of public-PoC exploitation landed inside 48 hours, and npm accounted for 87% of software-registry threats
    researchOverWatch telemetry puts a number on the collapsing patch window — and nation-state actors beat 24 hours on a web-application flaw

Where this entity is cited

  • research1

Source distribution

  • crowdstrike.com1 (50%)
  • siliconangle.com1 (50%)

explore in graph

Entries about VAULT PANDA (1)

2026-08-04 · view entry permalink →

NOTABLEexploitedNATOB2

CrowdStrike 2026 Threat Hunting Report: 88% of public-PoC exploitation landed inside 48 hours, and npm accounted for 87% of software-registry threats

CrowdStrike's Counter Adversary Operations team published its annual Threat Hunting Report on 2026-08-03, drawing on OverWatch managed-hunting and CrowdStrike Intelligence telemetry from what it describes only as "the past year" (CrowdStrike, 2026-08-03); reporting on the release puts that window at the 12 months to 30 June 2026 (SiliconANGLE, 2026-08-03). Only a few of its findings change a defender's decisions; those are the ones worth carrying.

The one that does most work is the exploitation-velocity measurement: "From January through June 2026, 88% of CrowdStrike-observed exploitation of vulnerabilities with a public PoC was conducted within 48 hours of the PoC's release." The named cases go faster still. China-nexus VAULT PANDA and GENESIS PANDA launched deliberate attacks within 24 hours of the public disclosure of a critical web-application flaw, and after the React2Shell disclosure OverWatch worked 800+ hunting leads across more than 80 victims in four days. For a Linux local privilege-escalation flaw disclosed on 29 April with a researcher PoC released the same day, OverWatch saw widespread exploit deployment the following day — roughly 94% of first-day events matching public PoC testing behaviour — and for the Belarus-nexus actor UMBRAL BISON, "They uncovered Belarus-nexus activity in just over 20 hours after public disclosure." CrowdStrike's own read is that this pattern predates frontier AI models but that those models are likely to compress the timeline further by accelerating vulnerability discovery and exploit development.

The practical consequence is a prioritisation input rather than a task: for an internet-reachable component, the arrival of a public proof-of-concept is the trigger, and waiting for a KEV listing or the next scheduled maintenance window puts the decision after the exploitation rather than before it. That reframing bites hardest on the exposure classes this constituency runs at the perimeter — the edge appliances, management planes and web applications that need no user interaction to reach.

On the software supply chain, the concentration figure is the useful one: "87% of identified software registry threats in the first half of 2026 involved npm packages", which CrowdStrike attributes to JavaScript's dependency-chain scale and automatic install scripts. The named activity adds tradecraft detail on a cluster this store already tracks under the name Sapphire Sleet, one of whose recorded aliases is CrowdStrike's STARDUST CHOLLIMA: the DPRK-nexus actor used stolen maintainer credentials in March 2026 to compromise the axios npm package and deliver platform-specific variants of its ZshBucket malware, and in June 2026 injected a malicious npm package as a dependency into at least 131 Mastra AI framework packages — which CrowdStrike reads as trusted AI building blocks becoming supply-chain targets. A separate financially motivated actor, ALTERED SPIDER, compromised more than 300 software dependencies in one day, harvested credentials and pivoted into cloud environments.

Three identity and AI observations complete the picture without carrying separate action, because the underlying tradecraft is already covered in this store's operational entries. Vishing intrusions in H1 2026 doubled against H2 2025, with CrowdStrike recording one case in which an eCrime operator moved from account takeover to SaaS data theft in under five minutes. Monthly device-code phishing attempts rose 15x over six months. And on the defender's side of the ledger, "AI agent-triggered detection leads now surface 2.5x more threat leads than manually driven activity", which CrowdStrike frames as making it harder to separate malicious activity from expected AI-driven behaviour — a triage-volume problem rather than an attacker capability gain. One LLMjacking campaign generated nearly 200,000 API requests in two minutes against a hijacked service.

From January through June 2026, 88% of CrowdStrike-observed exploitation of vulnerabilities with a public PoC was conducted within 48 hours of the PoC’s release.

They uncovered Belarus-nexus activity in just over 20 hours after public disclosure.

87% of identified software registry threats in the first half of 2026 involved npm packages.

CrowdStrike Counter Adversary Operations 2026-08-03

Builds on: 2026-07-30/amazon-dprk-attribution-npm-typo-crypto-rehearsal · 2026-05-09/cve-2026-31431-copy-fail-cisa-kev-deadline-2026-05-15-approa

annual-report04 Aug 04:50Zmulti-sourceOpen finding ↗