Wiley, B. et al. (2021, December 29). OverWatch Exposes AQUATIC PANDA in Possession of Log4Shell Exploit Tools During Hands-on Intrusion Attempt. Retrieved January 18, 2022.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1003.001 LSASS Memory |
GroupAquatic Panda | Aquatic Panda has attempted to harvest credentials through LSASS memory dumping. |
| T1007 System Service Discovery |
GroupAquatic Panda | Aquatic Panda has attempted to discover services for third party EDR products. |
| T1027.010 Command Obfuscation |
GroupAquatic Panda | Aquatic Panda has encoded PowerShell commands in Base64. |
| T1059.001 PowerShell |
GroupAquatic Panda | Aquatic Panda has downloaded additional scripts and executed Base64 encoded commands in PowerShell. |
| T1059.003 Windows Command Shell |
GroupAquatic Panda | Aquatic Panda has attempted and failed to run Bash commands on a Windows host by passing them to |
| T1070.004 File Deletion |
GroupAquatic Panda | Aquatic Panda has deleted malicious executables from compromised machines. |
| T1082 System Information Discovery |
GroupAquatic Panda | Aquatic Panda has used native OS commands to understand privilege levels and system details. |
| T1105 Ingress Tool Transfer |
GroupAquatic Panda | Aquatic Panda has downloaded additional malware onto compromised hosts. |
| T1518.001 Security Software Discovery |
GroupAquatic Panda | Aquatic Panda has attempted to discover third party endpoint detection and response (EDR) tools on compromised systems. |
| T1560.001 Archive via Utility |
GroupAquatic Panda | Aquatic Panda has used several publicly available tools, including WinRAR and 7zip, to compress collected files and memory dumps prior to exfiltration. |
| T1574.001 DLL |
GroupAquatic Panda | Aquatic Panda has used DLL search-order hijacking to load `exe`, `dll`, and `dat` files into memory. Aquatic Panda loaded a malicious DLL into the legitimate Windows Security Health Service executable ( |
| T1588.001 Malware |
GroupAquatic Panda | Aquatic Panda has acquired and used njRAT in its operations. |
| T1588.002 Tool |
GroupAquatic Panda | Aquatic Panda has acquired and used Cobalt Strike in its operations. |
| T1595.002 Vulnerability Scanning |
GroupAquatic Panda | Aquatic Panda has used publicly accessible DNS logging services to identify servers vulnerable to Log4j (CVE 2021-44228). |
| T1685 Disable or Modify Tools |
GroupAquatic Panda | Aquatic Panda has attempted to stop endpoint detection and response (EDR) tools on compromised systems. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.