← threatfilter.dev / all groups / Aquatic Panda
Aquatic Panda
Overview
Aquatic Panda is a suspected China-based threat group with a dual mission of intelligence collection and industrial espionage. Active since at least May 2020, Aquatic Panda has primarily targeted entities in the telecommunications, technology, and government sectors.
Targets
Covid-19 Research Organizations · Cryptocurrency · Education · Gambling Companies · Government Institutions · Media · Medical · Pro-democracy And Human Rights Political Organizations · Religious Organization · Telecommunications
Regions
Australia · China · France · Germany · Hong Kong · Japan · Mongolia · Nepal · Nigeria · Philippines · Taiwan · Thailand · United Arab Emirates · United States · Vietnam
Capabilities
- Custom malware/implant development — ATT&CK: 5 attributed custom malware families
TTPs — 35 techniques across 11 tactics
Reconnaissance
-
T1595.002Vulnerability Scanning
Execution
-
T1047Windows Management Instrumentation -
T1059.001PowerShell -
T1059.003Windows Command Shell -
T1059.004Unix Shell
Persistence
-
T1543.003Windows Service
Stealth
-
T1027.010Command Obfuscation -
T1036.004Masquerade Task or Service -
T1036.005Match Legitimate Resource Name or Location -
T1070.003Clear Command History -
T1070.004File Deletion -
T1078.002Domain Accounts -
T1218.011Rundll32 -
T1574.001DLL -
T1574.006Dynamic Linker Hijacking
Defense Impairment
-
T1112Modify Registry -
T1685Disable or Modify Tools -
T1685.005Clear Windows Event Logs
Credential Access
-
T1003.001LSASS Memory
Discovery
-
T1007System Service Discovery -
T1033System Owner/User Discovery -
T1082System Information Discovery -
T1087Account Discovery -
T1518.001Security Software Discovery -
T1654Log Enumeration
Lateral Movement
-
T1021Remote Services -
T1021.001Remote Desktop Protocol -
T1021.002SMB/Windows Admin Shares -
T1021.004SSH -
T1550.002Pass the Hash
Collection
-
T1005Data from Local System -
T1560.001Archive via Utility
Command and Control
-
T1105Ingress Tool Transfer
Tools & malware (6)
Wevtutil · Winnti for Windows · njRAT · Cobalt Strike · ShadowPad · Winnti for Linux