Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors FishMedley

Also known as: Earth Lusca, Aquatic Panda, Red Dev 10, TAG 22, DeputyDog, tracked as, watering hole

Description

FishMedley — also catalogued as FishMonger, Earth Lusca, Aquatic Panda, Red Dev 10, TAG 22 and others—has been identified by multiple security research teams as a China‑aligned threat actor operating under the I‑SOON contractor and the larger Winnti Group umbrella. In Operation FishMedley, the actors leveraged a suite of backdoors (ShadowPad, SodaMaster, Spyder) that bundle the ScatterBee DLL side‑load technique to achieve persistence on Windows machines. They deploy these implants through PowerShell scripts and Windows command shell commands, often triggered by watering‑hole injections into publicly visible web assets used by government, NGO and think‑tank organizations. The group’s methodology includes sophisticated credential access tactics: dumping LSASS memory and the SAM hive via rundll32, extracting browser‑stored credentials, and using custom password‑filter DLLs to exfiltrate passwords. They also abuse privileged domain‑administrator accounts for lateral movement, share implants over SMB with Impacket, and scan internal networks using fscan and NetBIOS scanners. Exfiltration frequently occurs through Dropbox or a proprietary exfiltration utility, accompanied by raw TCP/UDP traffic toward command‑and‑control domains. Attribution evidence links the operation to FishMonger’s known infrastructure and the I‑SOON contractor’s involvement in prior campaigns. The use of Chinese‑aligned implants, coupled with legal indictments against I‑SOON personnel for global espionage, corroborates a state‑backed or sponsored profile. While there are gaps regarding specific sub‑team assignments within Winnti, the breadth of tools and targeting demonstrates a coordinated threat actor capable of wide regional reach.

Goals & Targeting

Targeted Sectors

Government
Non profit
Think tank
Defense
Education
Telecommunications
Financial services
Manufacturing
Critical infrastructure
Aerospace
Media

Targeted Countries / Regions

CN
US
TW
FR
TR
BY
UA
RU

AI Analysis

Grounded in web research
· analyzed in 3 chunks · 1 day ago

Executive Summary

FishMedley (also known as FishMonger, Earth Lusca, Aquatic Panda and other aliases) is a China‑aligned cyber‑espionage actor linked to the I‑SOON contractor and the Winnti Group umbrella. The group executed Operation FishMedley, targeting governments, NGOs and think‑tanks across Asia, Europe and the United States with sophisticated implants such as ShadowPad, SodaMaster and Spyder, leveraging watering‑hole attacks, privileged credentials and Dropbox for exfiltration. Their campaign demonstrates advanced persistence techniques, credential theft and broad geographic reach.

Goals & Targeting

FishMedley’s strategic objectives appear to be focused on gathering high‑value political and commercial intelligence from sovereign states, NGOs, think‑tanks and critical infrastructure providers. By compromising privileged accounts and utilizing persistent implants, the group seeks to maintain long‑term presence for continuous data exfiltration and surveillance, thereby supporting broader state intelligence or destabilization goals across multiple target nations.

Enhanced Description

Key Capabilities

  • Acquire domains and infrastructure
  • Deploy implants via PowerShell and Windows command shell scripts
  • Persist through Windows services and DLL side‑loading
  • Dump LSASS memory and SAM hives using rundll32
  • Extract credentials from web browsers and password filters
  • Leverage privileged domain‑administrator accounts for lateral movement
  • Conduct watering‑hole attacks on public web assets
  • Scan networks with fscan and NetBIOS detectors
  • Exfiltrate data via Dropbox or custom exfiltration tools

MITRE ATT&CK Tactics

Resource Development
Initial Access
Execution
Persistence
Privilege Escalation
Defense Evasion
Credential Access
Discovery
Lateral Movement
Command and Control
Exfiltration

ATT&CK Techniques

T1059.001
T1059.003
T1072
T1543.003
T1574.002
T1140
T1555.003
T1556.002
T1003.001
T1003.002
T1087.001
T1016
T1021.002
T1095
T1071.001
T1046
T1083
T1078
T1041
T1189
T1583.001
T1583.004

Software / Tooling

ShadowPad
SodaMaster
Spyder
Impacket
Cobalt Strike
FunnySwitch
SprySOCKS
BIOPASS RAT
fscan
NetBIOS scanner
Dropbox exfil tool
custom password‑exfiltration tool

Campaigns & Victims

Operation FishMedley represents a large‑scale, multi‑phase intrusion that began in early 2023 and continued into late 2023. The actor targeted governments, NGOs, think‑tanks and other high‑profile organizations across Asia, Europe and the United States. Typical patterns include initial watering‑hole compromise via compromised public web servers or GlassFish applications, followed by rapid lateral movement using stolen domain‑admin credentials, the installation of ShadowPad/SodaMaster/Spyder backdoors, and the deployment of Dropbox‑based exfiltration channels. The campaign’s tempo was high, with multiple compromised accounts observed each week, indicating robust operational capacity and coordination. These tactics also suggest a preference for leveraging existing, widely used software ecosystems (e.g., Windows services, PowerShell) to avoid triggering defensive controls early on, while maintaining stealthy persistence through DLL side‑loading and registry manipulation. The combination of credential dumping, privileged account usage and exfiltration via cloud services demonstrates a sophisticated threat actor capable of adapting its toolkit to evade detection across diverse environments.

IOC Patterns

  • Domain
  • Server
  • Injectable implant indicators (ShadowPad/SodaMaster/Spyder)
  • Cobalt Strike beacon artifacts
  • Dropbox exfiltration patterns
  • Network service scanning signatures (fscan, NetBIOS)
  • Privileged domain administrator usage indicators

Recommended Actions

  • Monitor inbound and outbound traffic to known ShadowPad and SodaMaster C&C domains
  • Detect DLL side‑loading of malicious DLLs such as log.dll into legitimate executables like Bitdefender
  • Restrict PowerShell usage that downloads binaries from external sources
  • Audit LSASS memory dump activity via rundll32 and registry export of SAM hives
  • Segment networks to limit lateral movement of domain admin accounts
  • Deploy IDS/UEBA sensors for fscan and NetBIOS scanning activity
  • Implement file‑integrity monitoring for known implant binary patterns
  • Block or scrutinize outbound traffic through Dropbox unless a business exception exists
  • Track and filter Cobalt Strike beacon traffic via Web Protocols (T1071.001)
  • Enforce least privilege and MFA for domain administrator accounts
  • Maintain endpoint protection platforms up‑to‑date and apply critical patches

Suggested Tags

China-aligned threat actor
APT group
FishMonger
Winnti Group umbrella
I-SOON contractor
ShadowPad backdoor
SodaMaster backdoor
Operation FishMedley campaign
government agency target
NGO target
think‑tank target
Aquatic Panda
Earth Lusca
Red Dev 10
TAG-22
Espionage
Watering‑hole attacker
Privileged credential abuse
Winnti Group affiliate

Confidence Assessment

Confidence in the attribution of FishMedley to a China‑aligned actor linked with I‑SOON and Winnti is moderately high, supported by multiple independent research reports, legal indictments, and shared tool signatures. However, gaps remain regarding specific sub-team organization within Winnti, precise deployment timelines for each implant variant, and the full extent of cloud-based exfiltration infrastructure. Continued intelligence sharing and technical monitoring are recommended to refine these aspects.

ATT&CK Techniques

Software / Tooling

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

Filename 5 Domain 6 IPv4 Address 5 SHA-1 Hash 4

References

Intel Summary

25

Techniques

46

Tools

0

Campaigns

40

IOCs

0

Observed Data

12

Tactics

Tags

APT
Backdoor / C2
Government Targeting
China-aligned threat actor
APT group
FishMonger
Winnti Group umbrella
I-SOON contractor
ShadowPad backdoor
SodaMaster backdoor
Operation FishMedley campaign
government agency target
NGO target
think‑tank target
Aquatic Panda
Earth Lusca
Red Dev 10
TAG-22
Espionage
Watering‑hole attacker
Privileged credential abuse
Winnti Group affiliate

Details

Type
Unknown
Primary Motivation
Espionage
Country of Origin
China (CN)
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.