Cyber threat actor
Naikon
PLA, Chengdu MR Second Technical Reconnaissance Bureau · active since 2010
Focused on South China Sea regional intelligence, military, diplomatic and economic targets in ASEAN states.
Aliases
Override PandaPLA Unit 78020
Primary targets
ASEAN militaries Philippines Vietnam Indonesia Malaysia
MITRE ATT&CK techniques
3 techniques mapped · click any technique ID to open the MITRE ATT&CK entry, any CVE to view its NVD record, or any citation for source reporting.
| Tactic | Technique | Procedure | Targets | Citation |
|---|---|---|---|---|
| Initial Access | T1566.001 Spearphishing Attachment | Regional ASEAN-themed lures targeting militaries and foreign ministries. | Philippines, Vietnam, Indonesia, Malaysia | Check Point Naikon |
| Persistence | T1543.003 Aria-body backdoor (Windows Service) | Aria-body loader installed as service for long-dwell collection in ASEAN gov networks. | - | Check Point Naikon |
| Exfiltration | T1041 Exfiltration Over C2 Channel | Long-dwell, low-volume exfil of military and diplomatic documents related to the South China Sea. | - | Check Point Naikon |