CrowdStrike. (2023). 2022 Falcon OverWatch Threat Hunting Report. Retrieved May 20, 2024.
Not cited by any technique.
None recorded.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1005 Data from Local System |
GroupAquatic Panda | Aquatic Panda captured local Windows security event log data from victim machines using the |
| T1021 Remote Services |
GroupAquatic Panda | Aquatic Panda used remote scheduled tasks to install malicious software on victim systems during lateral movement actions. |
| T1021.001 Remote Desktop Protocol |
GroupAquatic Panda | Aquatic Panda leveraged stolen credentials to move laterally via RDP in victim environments. |
| T1021.002 SMB/Windows Admin Shares |
GroupAquatic Panda | Aquatic Panda used remote shares to enable lateral movement in victim environments. |
| T1021.004 SSH |
GroupAquatic Panda | Aquatic Panda used SSH with captured user credentials to move laterally in victim environments. |
| T1033 System Owner/User Discovery |
GroupAquatic Panda | Aquatic Panda gathers information on recently logged-in users on victim devices. |
| T1036.004 Masquerade Task or Service |
GroupAquatic Panda | Aquatic Panda created new, malicious services using names such as |
| T1036.005 Match Legitimate Resource Name or Location |
GroupAquatic Panda | Aquatic Panda renamed or moved malicious binaries to legitimate locations to evade defenses and blend into victim environments. |
| T1047 Windows Management Instrumentation |
GroupAquatic Panda | Aquatic Panda used WMI for lateral movement in victim environments. |
| T1059.004 Unix Shell |
GroupAquatic Panda | Aquatic Panda used malicious shell scripts in Linux environments following access via SSH to install Linux versions of Winnti malware. |
| T1070.003 Clear Command History |
GroupAquatic Panda | Aquatic Panda cleared command history in Linux environments to remove traces of activity after operations. |
| T1070.004 File Deletion |
GroupAquatic Panda | Aquatic Panda has deleted malicious executables from compromised machines. |
| T1078.002 Domain Accounts |
GroupAquatic Panda | Aquatic Panda used multiple mechanisms to capture valid user accounts for victim domains to enable lateral movement and access to additional hosts in victim environments. |
| T1087 Account Discovery |
GroupAquatic Panda | Aquatic Panda used the |
| T1112 Modify Registry |
GroupAquatic Panda | Aquatic Panda modified the victim registry to enable the `RestrictedAdmin` mode feature, allowing for pass the hash behaviors to function via RDP. |
| T1218.011 Rundll32 |
GroupAquatic Panda | Aquatic Panda used rundll32.exe to proxy execution of a malicious DLL file identified as a keylogging binary. |
| T1543.003 Windows Service |
GroupAquatic Panda | Aquatic Panda created new Windows services for persistence that masqueraded as legitimate Windows services via name change. |
| T1550.002 Pass the Hash |
GroupAquatic Panda | Aquatic Panda used a registry edit to enable a Windows feature called |
| T1560.001 Archive via Utility |
GroupAquatic Panda | Aquatic Panda has used several publicly available tools, including WinRAR and 7zip, to compress collected files and memory dumps prior to exfiltration. |
| T1574.001 DLL |
GroupAquatic Panda | Aquatic Panda has used DLL search-order hijacking to load `exe`, `dll`, and `dat` files into memory. Aquatic Panda loaded a malicious DLL into the legitimate Windows Security Health Service executable ( |
| T1574.006 Dynamic Linker Hijacking |
GroupAquatic Panda | Aquatic Panda modified the |
| T1654 Log Enumeration |
GroupAquatic Panda | Aquatic Panda enumerated logs related to authentication in Linux environments prior to deleting selective entries for defense evasion purposes. |
| T1685.005 Clear Windows Event Logs |
GroupAquatic Panda | Aquatic Panda clears Windows Event Logs following activity to evade defenses. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.