Deep Panda
Also known as: Shell Crew · WebMasters · KungFu Kittens · PinkPanther · Black Vine
Overview
Deep Panda is a suspected Chinese threat group known to target many industries, including government, defense, financial, and telecommunications. The intrusion into healthcare company Anthem has been attributed to Deep Panda. This group is also known as Shell Crew, WebMasters, KungFu Kittens, and PinkPanther. Deep Panda also appears to be known as Black Vine based on the attribution of both group names to the Anthem intrusion. Some analysts track Deep Panda and APT19 as the same group, but it is unclear from open source information if the groups are the same.
Naming & attribution
Deep Panda is tracked under 6 names across the industry. It uses 10 documented ATT&CK techniques — more than 30% of the 174 groups tracked here.
| Name | First reported by |
|---|---|
| Shell Crew | RSA Incident Response |
| WebMasters | RSA Incident Response |
| KungFu Kittens | RSA Incident Response |
| PinkPanther | RSA Incident Response |
| Black Vine | DiMaggio, J. |
| DEEP PANDA | Alperovitch, D |
Closest groups by technique overlap
Computed from shared ATT&CK techniques. Overlap is not attribution — distinct actors converge on the same tradecraft — but a high share is a useful pivot.
- ToddyCat — 6 shared techniques (21% overlap)
- APT3 China — 7 shared techniques (15% overlap)
- GALLIUM China — 5 shared techniques (14% overlap)
- Blue Mockingbird — 4 shared techniques (14% overlap)
- Play — 4 shared techniques (13% overlap)
- Stealth Falcon — 3 shared techniques (13% overlap)
Malware families with current indicators
One family attributed to Deep Panda, carrying 1 indicators currently tracked from abuse.ch ThreatFox, MalwareBazaar, URLhaus and SSLBL. MITRE documents what a group does; this is what its tooling is doing now.
- Sakula 1 indicators
Browse or copy the indicators by hash, domain, IP or URL, filtered by age from 1 day to 3 years.
Targets
Finance · Military · Non-profit Organisation · Private sector · Technology
Regions
United States
Capabilities
- Custom malware/implant development — ATT&CK: 4 attributed custom malware families
TTPs — 10 techniques across 6 tactics
Execution
-
T1047Windows Management Instrumentation -
T1059.001PowerShell
Persistence
-
T1505.003Web Shell
Privilege Escalation
-
T1546.008Accessibility Features
Stealth
-
T1027.005Indicator Removal from Tools -
T1218.010Regsvr32 -
T1564.003Hidden Window
Discovery
-
T1018Remote System Discovery -
T1057Process Discovery
Lateral Movement
-
T1021.002SMB/Windows Admin Shares
Tools & malware (7)
Mivast · Ping · Net · StreamEx · Sakula · Tasklist · Derusbi
Reporting (3)
- ICIT Brief - China’s Espionage Dynasty: Economic Death by a Thousand Cuts — Scott, J. and Spaniel, D
- The Black Vine cyberespionage group — DiMaggio, J.
- The Anthem Hack: All Roads Lead to China — ThreatConnect Research Team