Threat group.View on attack.mitre.org
Aquatic Panda is a suspected China-based threat group with a dual mission of intelligence collection and industrial espionage. Active since at least May 2020, Aquatic Panda has primarily targeted entities in the telecommunications, technology, and government sectors.
| Technique | Procedure example |
|---|---|
| T1003.001 LSASS Memory |
Aquatic Panda has attempted to harvest credentials through LSASS memory dumping. |
| T1005 Data from Local System |
Aquatic Panda captured local Windows security event log data from victim machines using the |
| T1007 System Service Discovery |
Aquatic Panda has attempted to discover services for third party EDR products. |
| T1021 Remote Services |
Aquatic Panda used remote scheduled tasks to install malicious software on victim systems during lateral movement actions. |
| T1021.001 Remote Desktop Protocol |
Aquatic Panda leveraged stolen credentials to move laterally via RDP in victim environments. |
| T1021.002 SMB/Windows Admin Shares |
Aquatic Panda used remote shares to enable lateral movement in victim environments. |
| T1021.004 SSH |
Aquatic Panda used SSH with captured user credentials to move laterally in victim environments. |
| T1027.010 Command Obfuscation |
Aquatic Panda has encoded PowerShell commands in Base64. |
| T1033 System Owner/User Discovery |
Aquatic Panda gathers information on recently logged-in users on victim devices. |
| T1036.004 Masquerade Task or Service |
Aquatic Panda created new, malicious services using names such as |
| T1036.005 Match Legitimate Resource Name or Location |
Aquatic Panda renamed or moved malicious binaries to legitimate locations to evade defenses and blend into victim environments. |
| T1047 Windows Management Instrumentation |
Aquatic Panda used WMI for lateral movement in victim environments. |
| T1059.001 PowerShell |
Aquatic Panda has downloaded additional scripts and executed Base64 encoded commands in PowerShell. |
| T1059.003 Windows Command Shell |
Aquatic Panda has attempted and failed to run Bash commands on a Windows host by passing them to |
| T1059.004 Unix Shell |
Aquatic Panda used malicious shell scripts in Linux environments following access via SSH to install Linux versions of Winnti malware. |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.