Aquatic Panda
MITRE ATT&CK: G0143 View on attack.mitre.org
Aliases: Aquatic Panda
- First seen
- 2020-05-01 00:00:00
- Primary motivation
- espionage
- Sophistication
- advanced
- Resource level
- government
- Actor type
- nation-state
- Profile updated
- 2026-07-07 12:02:15
Targeted industries: government-and-public-sector technology-and-telecommunications
Context
Aquatic Panda is a suspected China-based threat group with a dual mission of intelligence collection and industrial espionage. Active since at least May 2020, Aquatic Panda has primarily targeted entities in the telecommunications, technology, and government sectors.
Detection coverage
- 155 YARA rules
- 845 Sigma rules
Malware & tools used
- Account Discovery (attack-pattern)
- File Deletion (attack-pattern)
- Unix Shell (attack-pattern)
- SMB/Windows Admin Shares (attack-pattern)
- Masquerade Task or Service (attack-pattern)
- Dynamic Linker Hijacking (attack-pattern)
- Clear Command History (attack-pattern)
- Windows Service (attack-pattern)
- Pass the Hash (attack-pattern)
- DLL (attack-pattern)
- Remote Desktop Protocol (attack-pattern)
- Data from Local System (attack-pattern)
- Ingress Tool Transfer (attack-pattern)
- System Service Discovery (attack-pattern)
- Log Enumeration (attack-pattern)
- SSH (attack-pattern)
- Modify Registry (attack-pattern)
- Match Legitimate Resource Name or Location (attack-pattern)
- Malware (attack-pattern)
- Security Software Discovery (attack-pattern)
- Windows Command Shell (attack-pattern)
- Disable or Modify Tools (attack-pattern)
- System Owner/User Discovery (attack-pattern)
- Windows Management Instrumentation (attack-pattern)
- Tool (attack-pattern)
Reports & references
- CrowdStrike — Overwatch Exposes Aquatic Panda In Possession Of Log 4 Shell Exploit Tools (report)
- MITRE ATT&CK — G0143 (report)