Deep Panda

MITRE ATT&CK: G0009 View on attack.mitre.org

Aliases: Shell Crew, WebMasters, KungFu Kittens, PinkPanther, Black Vine, Deep Panda

First seen
2014-01-01 00:00:00
Primary motivation
espionage
Sophistication
advanced
Resource level
government
Actor type
nation-state
Profile updated
2026-07-07 11:47:48

Targeted industries: government-and-public-sector defense-and-aerospace financial-services healthcare-and-pharmaceutical technology-and-telecommunications

Targeted regions: country_code:us country_code:cn

Context

Deep Panda is a suspected Chinese threat group known to target many industries, including government, defense, financial, and telecommunications. The intrusion into healthcare company Anthem has been attributed to Deep Panda. This group is also known as Shell Crew, WebMasters, KungFu Kittens, and PinkPanther. Deep Panda also appears to be known as Black Vine based on the attribution of both group names to the Anthem intrusion. Some analysts track Deep Panda and APT19 as the same group, but it is unclear from open source information if the groups are the same.

Detection coverage

  • 8 YARA rules
  • 342 Sigma rules

Malware & tools used

  • Process Discovery (attack-pattern)
  • Remote System Discovery (attack-pattern)
  • Web Shell (attack-pattern)
  • Indicator Removal from Tools (attack-pattern)
  • Regsvr32 (attack-pattern)
  • Hidden Window (attack-pattern)
  • PowerShell (attack-pattern)
  • Accessibility Features (attack-pattern)
  • Windows Management Instrumentation (attack-pattern)
  • SMB/Windows Admin Shares (attack-pattern)
  • Net (malware)
  • Tasklist (malware)
  • StreamEx (malware)
  • Derusbi (malware)
  • Sakula (malware)
  • Ping (malware)
  • Mivast (malware)

Related threat objects

Reports & references

  • MITRE ATT&CK — G0009 (report)
  • web.archive.org — The Black Vine Cyberespionage Group (report)
  • web.archive.org — Icit Brief Chinas Espionage Dynasty Economic Death By A Thousand Cuts (report)
  • web.archive.org — Deep Thought Chinese Targeting National Security Think Tanks (report)
  • rsa.com — Rsa Incident Response Emerging Threat Profile Shell Crew (report)
  • threatconnect.com — The Anthem Hack All Roads Lead To China (report)

External references