news.mlab.sh
Threat intelligence
Threat actor

Aquatic Panda

Profile from actors.mlab.sh, coverage from our own index.

Suspected origin
China
Targeted countries
China
TLP
WHITE

(CrowdStrike) AQUATIC PANDA is a China-based targeted intrusion adversary with a dual mission of intelligence collection and industrial espionage. It has likely operated since at least May 2020. AQUATIC PANDA operations have primarily focused on entities in the telecommunications, technology and government sectors. AQUATIC PANDA relies heavily on Cobalt Strike, and its toolset includes the unique Cobalt Strike downloader tracked as FishMaster. AQUATIC PANDA has also been observed delivering njRAT payloads to targets.

Also known as

Aquatic PandaG0143

Tooling and malware

Cobalt StrikenjRATShadowPadWinnti for LinuxWinnti for WindowsWevtutil

MITRE ATT&CK techniques

T1005 Data from Local SystemT1105 Ingress Tool TransferT1112 Modify RegistryT1685 Disable or Modify ToolsT1007 System Service DiscoveryT1033 System Owner/User DiscoveryT1082 System Information DiscoveryT1087 Account DiscoveryT1654 Log EnumerationT1047 Windows Management InstrumentationT1021 Remote Services

Coverage 4