Deep Panda
MITRE ATT&CK: G0009 View on attack.mitre.org
Aliases: Shell Crew, WebMasters, KungFu Kittens, PinkPanther, Black Vine, Deep Panda
- First seen
- 2014-01-01 00:00:00
- Primary motivation
- espionage
- Sophistication
- advanced
- Resource level
- government
- Actor type
- nation-state
- Profile updated
- 2026-07-07 11:47:48
Targeted industries: government-and-public-sector defense-and-aerospace financial-services healthcare-and-pharmaceutical technology-and-telecommunications
Targeted regions: country_code:us country_code:cn
Context
Deep Panda is a suspected Chinese threat group known to target many industries, including government, defense, financial, and telecommunications. The intrusion into healthcare company Anthem has been attributed to Deep Panda. This group is also known as Shell Crew, WebMasters, KungFu Kittens, and PinkPanther. Deep Panda also appears to be known as Black Vine based on the attribution of both group names to the Anthem intrusion. Some analysts track Deep Panda and APT19 as the same group, but it is unclear from open source information if the groups are the same.
Detection coverage
- 8 YARA rules
- 342 Sigma rules
Malware & tools used
- Process Discovery (attack-pattern)
- Remote System Discovery (attack-pattern)
- Web Shell (attack-pattern)
- Indicator Removal from Tools (attack-pattern)
- Regsvr32 (attack-pattern)
- Hidden Window (attack-pattern)
- PowerShell (attack-pattern)
- Accessibility Features (attack-pattern)
- Windows Management Instrumentation (attack-pattern)
- SMB/Windows Admin Shares (attack-pattern)
- Net (malware)
- Tasklist (malware)
- StreamEx (malware)
- Derusbi (malware)
- Sakula (malware)
- Ping (malware)
- Mivast (malware)
Related threat objects
- HURRICANE PANDA (threat-actor)
- APT19 (threat-actor)
Reports & references
- MITRE ATT&CK — G0009 (report)
- web.archive.org — The Black Vine Cyberespionage Group (report)
- web.archive.org — Icit Brief Chinas Espionage Dynasty Economic Death By A Thousand Cuts (report)
- web.archive.org — Deep Thought Chinese Targeting National Security Think Tanks (report)
- rsa.com — Rsa Incident Response Emerging Threat Profile Shell Crew (report)
- threatconnect.com — The Anthem Hack All Roads Lead To China (report)
External references
- mitre-attack — G0009
- Deep Panda
- Shell Crew
- WebMasters
- KungFu Kittens
- PinkPanther
- Black Vine
- Alperovitch 2014
- Symantec Black Vine
- RSA Shell Crew
- ICIT China's Espionage Jul 2016
- ThreatConnect Anthem
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy