ATT&CKGroupsDeep Panda

Deep Panda

G0009

Threat group.View on attack.mitre.org

About this group

Deep Panda is a suspected Chinese threat group known to target many industries, including government, defense, financial, and telecommunications. The intrusion into healthcare company Anthem has been attributed to Deep Panda. This group is also known as Shell Crew, WebMasters, KungFu Kittens, and PinkPanther. Deep Panda also appears to be known as Black Vine based on the attribution of both group names to the Anthem intrusion. Some analysts track Deep Panda and APT19 as the same group, but it is unclear from open source information if the groups are the same.

Techniques used10

Procedure examples10

TechniqueProcedure example
T1018
Remote System Discovery

Deep Panda has used ping to identify other machines of interest.

T1021.002
SMB/Windows Admin Shares

Deep Panda uses net.exe to connect to network shares using net use commands with compromised credentials.

T1027.005
Indicator Removal from Tools

Deep Panda has updated and modified its malware, resulting in different hash values that evade detection.

T1047
Windows Management Instrumentation

The Deep Panda group is known to utilize WMI for lateral movement.

T1057
Process Discovery

Deep Panda uses the Microsoft Tasklist utility to list processes running on systems.

T1059.001
PowerShell

Deep Panda has used PowerShell scripts to download and execute programs in memory, without writing to disk.

T1218.010
Regsvr32

Deep Panda has used regsvr32.exe to execute a server variant of Derusbi in victim networks.

T1505.003
Web Shell

Deep Panda uses Web shells on publicly accessible Web servers to access victim networks.

T1546.008
Accessibility Features

Deep Panda has used the sticky-keys technique to bypass the RDP login screen on remote systems during intrusions.

T1564.003
Hidden Window

Deep Panda has used -w hidden to conceal PowerShell windows by setting the WindowStyle parameter to hidden.

Software7

Campaigns0

None recorded.

References5

  1. Alperovitch 2014 Open source
    Alperovitch, D. (2014, July 7). Deep in Thought: Chinese Targeting of National Security Think Tanks. Retrieved November 12, 2014.
  2. ICIT China's Espionage Jul 2016 Open source
    Scott, J. and Spaniel, D. (2016, July 28). ICIT Brief - China’s Espionage Dynasty: Economic Death by a Thousand Cuts. Retrieved June 7, 2018.
  3. RSA Shell Crew Open source
    RSA Incident Response. (2014, January). RSA Incident Response Emerging Threat Profile: Shell Crew. Retrieved January 14, 2016.
  4. Symantec Black Vine Open source
    DiMaggio, J.. (2015, August 6). The Black Vine cyberespionage group. Retrieved January 26, 2016.
  5. ThreatConnect Anthem Open source
    ThreatConnect Research Team. (2015, February 27). The Anthem Hack: All Roads Lead to China. Retrieved January 26, 2016.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.