Threat group.View on attack.mitre.org
Deep Panda is a suspected Chinese threat group known to target many industries, including government, defense, financial, and telecommunications. The intrusion into healthcare company Anthem has been attributed to Deep Panda. This group is also known as Shell Crew, WebMasters, KungFu Kittens, and PinkPanther. Deep Panda also appears to be known as Black Vine based on the attribution of both group names to the Anthem intrusion. Some analysts track Deep Panda and APT19 as the same group, but it is unclear from open source information if the groups are the same.
| Technique | Procedure example |
|---|---|
| T1018 Remote System Discovery |
Deep Panda has used ping to identify other machines of interest. |
| T1021.002 SMB/Windows Admin Shares |
Deep Panda uses net.exe to connect to network shares using |
| T1027.005 Indicator Removal from Tools |
Deep Panda has updated and modified its malware, resulting in different hash values that evade detection. |
| T1047 Windows Management Instrumentation |
The Deep Panda group is known to utilize WMI for lateral movement. |
| T1057 Process Discovery |
Deep Panda uses the Microsoft Tasklist utility to list processes running on systems. |
| T1059.001 PowerShell |
Deep Panda has used PowerShell scripts to download and execute programs in memory, without writing to disk. |
| T1218.010 Regsvr32 |
Deep Panda has used regsvr32.exe to execute a server variant of Derusbi in victim networks. |
| T1505.003 Web Shell |
Deep Panda uses Web shells on publicly accessible Web servers to access victim networks. |
| T1546.008 Accessibility Features |
Deep Panda has used the sticky-keys technique to bypass the RDP login screen on remote systems during intrusions. |
| T1564.003 Hidden Window |
Deep Panda has used |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.