ATT&CKReferencesCrowdStrike AQUATIC PANDA December 2021

CrowdStrike AQUATIC PANDA December 2021

Wiley, B. et al. (2021, December 29). OverWatch Exposes AQUATIC PANDA in Possession of Log4Shell Exploit Tools During Hands-on Intrusion Attempt. Retrieved January 18, 2022.

Open the source

Techniques0

Not cited by any technique.

Groups1

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples15

TechniqueUsed byProcedure example
T1003.001
LSASS Memory
GroupAquatic Panda

Aquatic Panda has attempted to harvest credentials through LSASS memory dumping.

T1007
System Service Discovery
GroupAquatic Panda

Aquatic Panda has attempted to discover services for third party EDR products.

T1027.010
Command Obfuscation
GroupAquatic Panda

Aquatic Panda has encoded PowerShell commands in Base64.

T1059.001
PowerShell
GroupAquatic Panda

Aquatic Panda has downloaded additional scripts and executed Base64 encoded commands in PowerShell.

T1059.003
Windows Command Shell
GroupAquatic Panda

Aquatic Panda has attempted and failed to run Bash commands on a Windows host by passing them to cmd /C.

T1070.004
File Deletion
GroupAquatic Panda

Aquatic Panda has deleted malicious executables from compromised machines.

T1082
System Information Discovery
GroupAquatic Panda

Aquatic Panda has used native OS commands to understand privilege levels and system details.

T1105
Ingress Tool Transfer
GroupAquatic Panda

Aquatic Panda has downloaded additional malware onto compromised hosts.

T1518.001
Security Software Discovery
GroupAquatic Panda

Aquatic Panda has attempted to discover third party endpoint detection and response (EDR) tools on compromised systems.

T1560.001
Archive via Utility
GroupAquatic Panda

Aquatic Panda has used several publicly available tools, including WinRAR and 7zip, to compress collected files and memory dumps prior to exfiltration.

T1574.001
DLL
GroupAquatic Panda

Aquatic Panda has used DLL search-order hijacking to load `exe`, `dll`, and `dat` files into memory. Aquatic Panda loaded a malicious DLL into the legitimate Windows Security Health Service executable (SecurityHealthService.exe) to execute malicious code on victim systems.

T1588.001
Malware
GroupAquatic Panda

Aquatic Panda has acquired and used njRAT in its operations.

T1588.002
Tool
GroupAquatic Panda

Aquatic Panda has acquired and used Cobalt Strike in its operations.

T1595.002
Vulnerability Scanning
GroupAquatic Panda

Aquatic Panda has used publicly accessible DNS logging services to identify servers vulnerable to Log4j (CVE 2021-44228).

T1685
Disable or Modify Tools
GroupAquatic Panda

Aquatic Panda has attempted to stop endpoint detection and response (EDR) tools on compromised systems.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.