Aquatic Panda
Aliases: None listed
Aquatic Panda is a suspected China-based threat group with a dual mission of intelligence collection and industrial espionage. Active since at least May 2020, Aquatic Panda has primarily targeted entities in the telecommunications, technology, and government sectors.
Open interactive actor investigation
ATT&CK techniques
T1027.010
Command ObfuscationT1087
Account DiscoveryT1070.004
File DeletionT1059.004
Unix ShellT1021.002
SMB/Windows Admin SharesT1036.004
Masquerade Task or ServiceT1574.006
Dynamic Linker HijackingT1070.003
Clear Command HistoryT1543.003
Windows ServiceT1550.002
Pass the HashT1574.001
DLL Search Order HijackingT1021.001
Remote Desktop ProtocolT1005
Data from Local SystemT1070.001
Clear Windows Event LogsT1105
Ingress Tool TransferT1007
System Service DiscoveryT1654
Log EnumerationT1021.004
SSHT1112
Modify RegistryT1036.005
Match Legitimate Name or LocationT1588.001
MalwareT1518.001
Security Software DiscoveryT1059.003
Windows Command ShellT1562.001
Disable or Modify ToolsT1033
System Owner/User DiscoveryT1047
Windows Management InstrumentationT1588.002
ToolT1595.002
Vulnerability ScanningT1003.001
LSASS MemoryT1021
Remote ServicesT1082
System Information DiscoveryT1218.011
Rundll32T1078.002
Domain AccountsT1560.001
Archive via UtilityT1059.001
PowerShell
Command ObfuscationT1087
Account DiscoveryT1070.004
File DeletionT1059.004
Unix ShellT1021.002
SMB/Windows Admin SharesT1036.004
Masquerade Task or ServiceT1574.006
Dynamic Linker HijackingT1070.003
Clear Command HistoryT1543.003
Windows ServiceT1550.002
Pass the HashT1574.001
DLL Search Order HijackingT1021.001
Remote Desktop ProtocolT1005
Data from Local SystemT1070.001
Clear Windows Event LogsT1105
Ingress Tool TransferT1007
System Service DiscoveryT1654
Log EnumerationT1021.004
SSHT1112
Modify RegistryT1036.005
Match Legitimate Name or LocationT1588.001
MalwareT1518.001
Security Software DiscoveryT1059.003
Windows Command ShellT1562.001
Disable or Modify ToolsT1033
System Owner/User DiscoveryT1047
Windows Management InstrumentationT1588.002
ToolT1595.002
Vulnerability ScanningT1003.001
LSASS MemoryT1021
Remote ServicesT1082
System Information DiscoveryT1218.011
Rundll32T1078.002
Domain AccountsT1560.001
Archive via UtilityT1059.001
PowerShell