Nightshade Panda, also known by aliases such as APT9, FlowerLady, FlowerShow, Group 27, and Red Pegasus, is a persistent threat actor assessed with high confidence to be of Chinese origin, first observed in early August 2013. This group's primary motivation is cyber-espionage and information theft, focusing on gathering sensitive intelligence from targeted entities. What distinguishes Nightshade Panda is its meticulous operational security, its sustained presence within compromised networks, and its use of custom malware variants, including specialized versions of PlugX and Poison Ivy. The group operates under several names and is often tracked by the broader cybersecurity community as APT9.