Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors Deep Panda

Also known as: Shell Crew, WebMasters, KungFu Kittens, PinkPanther, Black Vine, Deep Panda, APT19, Group 13, Sh3llCr3w, Winnti Group, Sandworm Team, tracked as, Operation Cleaver, a separate entity, APT28, VOLTZITE, for follow-on operations, SportsFans, Unit 61398

Description

Deep Panda is an advanced threat actor believed to have ties to Chinese state-sponsored activities. It operates under numerous aliases—Shell Crew, WebMasters, KungFu Kittens, PinkPanther, Black Vine, APT19, Winnti Group, Sandworm Team, among others—which has caused significant confusion in attribution efforts. The group's notable footprint began with the 2018 compromise of healthcare provider Anthem, where investigators identified spear‑phishing attachments and the installation of a web shell to maintain persistence. Subsequent analyses have linked similar tactics to other actors such as APT19 and Winnti Group, suggesting shared infrastructure or toolkits. Operationally, Deep Panda employs a variety of attack vectors including malicious Office macros (RTF/XLSM), PowerShell scripts, Windows Management Instrumentation queries, and web shells like China Chopper. Their campaigns show a clear emphasis on establishing footholds via publicly accessible hosting, then expanding lateral movement using SMB shares and WMI. The uncertainty surrounding the group’s exact identity stems from overlapping names, shared infrastructure, and differing industry reports, making precise attribution challenging yet highlighting the need for thorough monitoring of their broad threat landscape.

Goals & Targeting

Targeted Sectors

Government
Financial services
Telecommunications
Defense
Healthcare
Education
Manufacturing
Non profit
Energy
Media
Pharmaceutical
Critical infrastructure
Aviation
Aerospace
Think tank
Information technology
Hospitality
Legal services
Mining
Chemical
Retail
Transportation
Nuclear
Gaming
Maritime
Entertainment
Oil gas
Construction
Utilities
Food agriculture

Targeted Countries / Regions

CN
US
RU
IL
VN
SA
IR
JP
GB
IN
PK
AE
AU
KR
TW
UA
PL
SG
DE
TR
BY
RO
MX
ES
KP
CA
LB
FR
NG
IT
AZ
KZ

AI Analysis

Grounded in web research
· 1 day ago

Executive Summary

Deep Panda is a suspected Chinese espionage actor with a broad industry focus that includes government, finance, telecommunications, defense, healthcare and many other sectors. The group has been linked to high-profile intrusions such as the 2018 Anthem breach through spear‑phishing & web shell techniques. Their operations demonstrate long‑lasting persistence and multi‑stage campaigns aimed at gathering strategic and commercial intelligence.

Goals & Targeting

Deep Panda targets a diverse set of sectors with the primary objective of espionage—collecting strategic, technical, or commercial secrets. By focusing on governments, defense contractors, telecommunications firms, financial services, and healthcare providers, they aim to harvest sensitive policy documents, intellectual property, and proprietary data that can be leveraged for geopolitical advantage or economic gain. Their typical victims are organizations with high-value information: state agencies, critical infrastructure operators, major telecom operators, large financial institutions, and global defense contractors. The actor's choice of targets reflects an intent to gather intelligence across multiple domains to advance national interests in the cyber domain.

Enhanced Description

Key Capabilities

  • Deploys spear‑phishing with malicious Office attachments (RTF/XLSM)
  • Installs web shells such as China Chopper for persistence
  • Uses PowerShell and cmd scripts for execution and lateral movement
  • Leverages Windows Management Instrumentation (WMI) for discovery
  • Employs SMB/Windows Admin Shares for file transfer
  • Obfuscates payloads using Base64 encoding
  • Maintains stealth with hidden windows and registry modifications
  • Acquires infrastructure including VPN servers and domain names

MITRE ATT&CK Tactics

Execution
Persistence
Privilege Escalation
Defense Evasion
Credential Access
Discovery
Exfiltration
Command and Control

ATT&CK Techniques

T1059.001
T1047
T1033
T1064
T1082
T1071.001
T1566.001
T1218.010
T1112
T1027
T1027.005
T1545.003
T1505.003
T1583.001
T1583.004
T1189
T1204

Software / Tooling

PowerShell scripts
Web Shells (China Chopper)
Cobalt Strike (used for post‑exploitation phases)
Winnti Malware suite
Emissary
Machete
Akira
Carbanak
StreamEx

Campaigns & Victims

Deep Panda’s campaign lifecycle typically involves a prolonged initial compromise through spear‑phishing, followed by the deployment of web shells and PowerShell backdoors. They maintain long‑term persistence, often spanning months or years, and employ frequent lateral movement across networks via SMB shares and WMI. Victims are usually large enterprises or government institutions where valuable data resides; the actor selectively exfiltrates information relevant to national security or economic competition. Notable operations include the Anthem breach (2018) and suspected involvement in other incidents attributed to APT19 and Winnti, although attribution remains ambiguous due to overlapping tooling and infrastructure.

IOC Patterns

  • Spear‑phishing with malicious Office attachments (RTF/XLSM macros)
  • Web shell deployment on public hosting or bulletproof servers
  • Use of obscure domains such as TEMP.Veles, TEMP.Angels for C2
  • Base64‑encoded Command & Control traffic over HTTP/HTTPS
  • Hidden execution windows and registry persistence mechanisms

Recommended Actions

  • Employ multi‑factor authentication across all privileged services to mitigate phishing credential compromise.
  • Deploy email security gateways that scan attachments for macros and flag suspicious Office files.
  • Monitor network traffic for unusual SMB activity, WMI queries and HTTP packets carrying Base64 payloads.
  • Implement endpoint detection and response solutions capable of detecting hidden processes and registry modifications.
  • Segment critical networks and enforce least‑privilege access to limit lateral movement opportunities.
  • Regularly patch systems to close known CVEs (e.g., CVE-2017-0199) that the actor may exploit early in an attack.

Suggested Tags

APT
Chinese state-sponsored
cyberespionage
phishing
web shells
persistence
long‑term intrusion

Confidence Assessment

The data are drawn from publicly available reports and analyses, many of which reference overlapping aliases (Deep Panda, APT19, Winnti). Because attribution is inconsistent across sources, there is uncertainty about whether all activities are performed by a single unit. Additionally, most public details date to 2017‑2018, so recent tactics or infrastructure could differ. Confidence in the core capabilities and target sectors remains high, but gaps exist regarding current operational tempo, tool evolution, and precise attribution.

ATT&CK Techniques

Defense impairment
1 technique

Software / Tooling

Campaigns / Victims

Observed Data

No observed data linked yet.

References

  1. Alperovitch 2014 — Alperovitch, D. (2014, July 7). Deep in Thought: Chinese Targeting of National Security Think Tanks. Retrieved November 12, 2014.
  2. Symantec Black Vine — DiMaggio, J.. (2015, August 6). The Black Vine cyberespionage group. Retrieved January 26, 2016.
  3. RSA Shell Crew — RSA Incident Response. (2014, January). RSA Incident Response Emerging Threat Profile: Shell Crew. Retrieved January 14, 2016.
  4. ICIT China's Espionage Jul 2016 — Scott, J. and Spaniel, D. (2016, July 28). ICIT Brief - China’s Espionage Dynasty: Economic Death by a Thousand Cuts. Retrieved June 7, 2018.
  5. ThreatConnect Anthem — ThreatConnect Research Team. (2015, February 27). The Anthem Hack: All Roads Lead to China. Retrieved January 26, 2016.
  6. attack.mitre.org — Cited by web research for: Sandworm Team
  7. apt.etda.or.th — Cited by web research for: SportsFans
  8. docs.rapid7.com — Cited by web research for: Unit 61398
  9. attack.mitre.org — Cited by web research for: T1071
  10. learn.microsoft.com — Cited by web research for: Tsunami
  11. www.crowdstrike.com — Cited by web research for: CVE-2017-0199

Intel Summary

40

Techniques

58

Tools

3

Campaigns

35

IOCs

0

Observed Data

11

Tactics

Tags

APT
Healthcare Targeting
Government Targeting
espionage
cyber-espionage
government
defense
Chinese state-sponsored
cyberespionage
phishing
web shells
persistence
long‑term intrusion

Details

MITRE ID
G0009
Type
Unknown
Resource Level
Government
Primary Motivation
Espionage
Country of Origin
China (CN)
Confidence
90%
Added
Jul 13, 2026
STIX ID
intrusion-set--a653431d-6a5e-4600-8ad3-609b5af57064
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.