NEW: Group Profiler — instant APT intel lookup. Try it →

Aquatic Panda

G0143 China MITRE ATT&CK →

Overview

Aquatic Panda is a suspected China-based threat group with a dual mission of intelligence collection and industrial espionage. Active since at least May 2020, Aquatic Panda has primarily targeted entities in the telecommunications, technology, and government sectors.

Naming & attribution

Aquatic Panda is tracked under 1 names across the industry. It uses 35 documented ATT&CK techniques — more than 71% of the 174 groups tracked here.

Distinctive techniques

Techniques this group uses that are rare across the other 173 tracked groups — these carry more signal than the near-universal ones.

  • T1021 Remote Services — used by 3 of 174 groups
  • T1087 Account Discovery — used by 3 of 174 groups
  • T1574.006 Dynamic Linker Hijacking — used by 3 of 174 groups

Closest groups by technique overlap

Computed from shared ATT&CK techniques. Overlap is not attribution — distinct actors converge on the same tradecraft — but a high share is a useful pivot.

  • Wizard Spider Russia — 23 shared techniques (30% overlap)
  • Play — 14 shared techniques (30% overlap)
  • APT41 China — 26 shared techniques (29% overlap)
  • FIN8 — 16 shared techniques (29% overlap)
  • Blue Mockingbird — 12 shared techniques (27% overlap)
  • FIN13 — 17 shared techniques (24% overlap)

Targets

Covid-19 Research Organizations · Cryptocurrency · Education · Gambling Companies · Government Institutions · Media · Medical · Pro-democracy And Human Rights Political Organizations · Religious Organization · Telecommunications

Regions

Australia · China · France · Germany · Hong Kong · Japan · Mongolia · Nepal · Nigeria · Philippines · Taiwan · Thailand · United Arab Emirates · United States · Vietnam

Capabilities

  • Custom malware/implant development — ATT&CK: 5 attributed custom malware families

TTPs — 35 techniques across 11 tactics

Reconnaissance

Resource Development

Execution

Persistence

Defense Impairment

Credential Access

Lateral Movement

Collection

Command and Control

Tools & malware (6)

Wevtutil · Winnti for Windows · njRAT · Cobalt Strike · ShadowPad · Winnti for Linux

Reporting (1)