ATT&CKGroupsAquatic Panda

Aquatic Panda

G0143

Threat group.View on attack.mitre.org

About this group

Aquatic Panda is a suspected China-based threat group with a dual mission of intelligence collection and industrial espionage. Active since at least May 2020, Aquatic Panda has primarily targeted entities in the telecommunications, technology, and government sectors.

Techniques used35

Procedure examples35

TechniqueProcedure example
T1003.001
LSASS Memory

Aquatic Panda has attempted to harvest credentials through LSASS memory dumping.

T1005
Data from Local System

Aquatic Panda captured local Windows security event log data from victim machines using the wevtutil utility to extract contents to an evtx output file.

T1007
System Service Discovery

Aquatic Panda has attempted to discover services for third party EDR products.

T1021
Remote Services

Aquatic Panda used remote scheduled tasks to install malicious software on victim systems during lateral movement actions.

T1021.001
Remote Desktop Protocol

Aquatic Panda leveraged stolen credentials to move laterally via RDP in victim environments.

T1021.002
SMB/Windows Admin Shares

Aquatic Panda used remote shares to enable lateral movement in victim environments.

T1021.004
SSH

Aquatic Panda used SSH with captured user credentials to move laterally in victim environments.

T1027.010
Command Obfuscation

Aquatic Panda has encoded PowerShell commands in Base64.

T1033
System Owner/User Discovery

Aquatic Panda gathers information on recently logged-in users on victim devices.

T1036.004
Masquerade Task or Service

Aquatic Panda created new, malicious services using names such as Windows User Service to attempt to blend in with legitimate items on victim systems.

T1036.005
Match Legitimate Resource Name or Location

Aquatic Panda renamed or moved malicious binaries to legitimate locations to evade defenses and blend into victim environments.

T1047
Windows Management Instrumentation

Aquatic Panda used WMI for lateral movement in victim environments.

T1059.001
PowerShell

Aquatic Panda has downloaded additional scripts and executed Base64 encoded commands in PowerShell.

T1059.003
Windows Command Shell

Aquatic Panda has attempted and failed to run Bash commands on a Windows host by passing them to cmd /C.

T1059.004
Unix Shell

Aquatic Panda used malicious shell scripts in Linux environments following access via SSH to install Linux versions of Winnti malware.

View all 35 procedure examples

Software6

Campaigns0

None recorded.

References1

  1. CrowdStrike AQUATIC PANDA December 2021 Open source
    Wiley, B. et al. (2021, December 29). OverWatch Exposes AQUATIC PANDA in Possession of Log4Shell Exploit Tools During Hands-on Intrusion Attempt. Retrieved January 18, 2022.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.