NEW: Group Profiler — instant APT intel lookup. Try it →

Deep Panda

G0009 China Espionage MITRE ATT&CK →

Also known as: Shell Crew · WebMasters · KungFu Kittens · PinkPanther · Black Vine

Overview

Deep Panda is a suspected Chinese threat group known to target many industries, including government, defense, financial, and telecommunications. The intrusion into healthcare company Anthem has been attributed to Deep Panda. This group is also known as Shell Crew, WebMasters, KungFu Kittens, and PinkPanther. Deep Panda also appears to be known as Black Vine based on the attribution of both group names to the Anthem intrusion. Some analysts track Deep Panda and APT19 as the same group, but it is unclear from open source information if the groups are the same.

Naming & attribution

Deep Panda is tracked under 6 names across the industry. It uses 10 documented ATT&CK techniques — more than 30% of the 174 groups tracked here.

Who calls this group what — MITRE lists each alias with the report that used it, but not which vendor coined it.
NameFirst reported by
Shell CrewRSA Incident Response
WebMastersRSA Incident Response
KungFu KittensRSA Incident Response
PinkPantherRSA Incident Response
Black VineDiMaggio, J.
DEEP PANDAAlperovitch, D

Closest groups by technique overlap

Computed from shared ATT&CK techniques. Overlap is not attribution — distinct actors converge on the same tradecraft — but a high share is a useful pivot.

  • ToddyCat — 6 shared techniques (21% overlap)
  • APT3 China — 7 shared techniques (15% overlap)
  • GALLIUM China — 5 shared techniques (14% overlap)
  • Blue Mockingbird — 4 shared techniques (14% overlap)
  • Play — 4 shared techniques (13% overlap)
  • Stealth Falcon — 3 shared techniques (13% overlap)

Malware families with current indicators

One family attributed to Deep Panda, carrying 1 indicators currently tracked from abuse.ch ThreatFox, MalwareBazaar, URLhaus and SSLBL. MITRE documents what a group does; this is what its tooling is doing now.

  • Sakula 1 indicators

Browse or copy the indicators by hash, domain, IP or URL, filtered by age from 1 day to 3 years.

Targets

Finance · Military · Non-profit Organisation · Private sector · Technology

Regions

United States

Capabilities

  • Custom malware/implant development — ATT&CK: 4 attributed custom malware families

TTPs — 10 techniques across 6 tactics

Persistence

Privilege Escalation

Stealth

Lateral Movement

Tools & malware (7)

Mivast · Ping · Net · StreamEx · Sakula · Tasklist · Derusbi

Reporting (3)