Aquatic Panda

MITRE ATT&CK: G0143 View on attack.mitre.org

Aliases: Aquatic Panda

First seen
2020-05-01 00:00:00
Primary motivation
espionage
Sophistication
advanced
Resource level
government
Actor type
nation-state
Profile updated
2026-07-07 12:02:15

Targeted industries: government-and-public-sector technology-and-telecommunications

Context

Aquatic Panda is a suspected China-based threat group with a dual mission of intelligence collection and industrial espionage. Active since at least May 2020, Aquatic Panda has primarily targeted entities in the telecommunications, technology, and government sectors.

Detection coverage

  • 155 YARA rules
  • 845 Sigma rules

Malware & tools used

  • Account Discovery (attack-pattern)
  • File Deletion (attack-pattern)
  • Unix Shell (attack-pattern)
  • SMB/Windows Admin Shares (attack-pattern)
  • Masquerade Task or Service (attack-pattern)
  • Dynamic Linker Hijacking (attack-pattern)
  • Clear Command History (attack-pattern)
  • Windows Service (attack-pattern)
  • Pass the Hash (attack-pattern)
  • DLL (attack-pattern)
  • Remote Desktop Protocol (attack-pattern)
  • Data from Local System (attack-pattern)
  • Ingress Tool Transfer (attack-pattern)
  • System Service Discovery (attack-pattern)
  • Log Enumeration (attack-pattern)
  • SSH (attack-pattern)
  • Modify Registry (attack-pattern)
  • Match Legitimate Resource Name or Location (attack-pattern)
  • Malware (attack-pattern)
  • Security Software Discovery (attack-pattern)
  • Windows Command Shell (attack-pattern)
  • Disable or Modify Tools (attack-pattern)
  • System Owner/User Discovery (attack-pattern)
  • Windows Management Instrumentation (attack-pattern)
  • Tool (attack-pattern)

Reports & references

  • CrowdStrike — Overwatch Exposes Aquatic Panda In Possession Of Log 4 Shell Exploit Tools (report)
  • MITRE ATT&CK — G0143 (report)

External references