Also known as: Earth Lusca, Aquatic Panda, Red Dev 10, TAG 22, DeputyDog, tracked as, watering hole
FishMedley — also catalogued as FishMonger, Earth Lusca, Aquatic Panda, Red Dev 10, TAG 22 and others—has been identified by multiple security research teams as a China‑aligned threat actor operating under the I‑SOON contractor and the larger Winnti Group umbrella. In Operation FishMedley, the actors leveraged a suite of backdoors (ShadowPad, SodaMaster, Spyder) that bundle the ScatterBee DLL side‑load technique to achieve persistence on Windows machines. They deploy these implants through PowerShell scripts and Windows command shell commands, often triggered by watering‑hole injections into publicly visible web assets used by government, NGO and think‑tank organizations. The group’s methodology includes sophisticated credential access tactics: dumping LSASS memory and the SAM hive via rundll32, extracting browser‑stored credentials, and using custom password‑filter DLLs to exfiltrate passwords. They also abuse privileged domain‑administrator accounts for lateral movement, share implants over SMB with Impacket, and scan internal networks using fscan and NetBIOS scanners. Exfiltration frequently occurs through Dropbox or a proprietary exfiltration utility, accompanied by raw TCP/UDP traffic toward command‑and‑control domains. Attribution evidence links the operation to FishMonger’s known infrastructure and the I‑SOON contractor’s involvement in prior campaigns. The use of Chinese‑aligned implants, coupled with legal indictments against I‑SOON personnel for global espionage, corroborates a state‑backed or sponsored profile. While there are gaps regarding specific sub‑team assignments within Winnti, the breadth of tools and targeting demonstrates a coordinated threat actor capable of wide regional reach.
Targeted Sectors
Targeted Countries / Regions
Executive Summary
FishMedley (also known as FishMonger, Earth Lusca, Aquatic Panda and other aliases) is a China‑aligned cyber‑espionage actor linked to the I‑SOON contractor and the Winnti Group umbrella. The group executed Operation FishMedley, targeting governments, NGOs and think‑tanks across Asia, Europe and the United States with sophisticated implants such as ShadowPad, SodaMaster and Spyder, leveraging watering‑hole attacks, privileged credentials and Dropbox for exfiltration. Their campaign demonstrates advanced persistence techniques, credential theft and broad geographic reach.
Goals & Targeting
FishMedley’s strategic objectives appear to be focused on gathering high‑value political and commercial intelligence from sovereign states, NGOs, think‑tanks and critical infrastructure providers. By compromising privileged accounts and utilizing persistent implants, the group seeks to maintain long‑term presence for continuous data exfiltration and surveillance, thereby supporting broader state intelligence or destabilization goals across multiple target nations.
Enhanced Description
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
Operation FishMedley represents a large‑scale, multi‑phase intrusion that began in early 2023 and continued into late 2023. The actor targeted governments, NGOs, think‑tanks and other high‑profile organizations across Asia, Europe and the United States. Typical patterns include initial watering‑hole compromise via compromised public web servers or GlassFish applications, followed by rapid lateral movement using stolen domain‑admin credentials, the installation of ShadowPad/SodaMaster/Spyder backdoors, and the deployment of Dropbox‑based exfiltration channels. The campaign’s tempo was high, with multiple compromised accounts observed each week, indicating robust operational capacity and coordination. These tactics also suggest a preference for leveraging existing, widely used software ecosystems (e.g., Windows services, PowerShell) to avoid triggering defensive controls early on, while maintaining stealthy persistence through DLL side‑loading and registry manipulation. The combination of credential dumping, privileged account usage and exfiltration via cloud services demonstrates a sophisticated threat actor capable of adapting its toolkit to evade detection across diverse environments.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
Confidence in the attribution of FishMedley to a China‑aligned actor linked with I‑SOON and Winnti is moderately high, supported by multiple independent research reports, legal indictments, and shared tool signatures. However, gaps remain regarding specific sub-team organization within Winnti, precise deployment timelines for each implant variant, and the full extent of cloud-based exfiltration infrastructure. Continued intelligence sharing and technical monitoring are recommended to refine these aspects.
No campaigns linked yet.
No observed data linked yet.
25
Techniques
46
Tools
0
Campaigns
40
IOCs
0
Observed Data
12
Tactics