Also known as: Shell Crew, WebMasters, KungFu Kittens, PinkPanther, Black Vine, Deep Panda, APT19, Group 13, Sh3llCr3w, Winnti Group, Sandworm Team, tracked as, Operation Cleaver, a separate entity, APT28, VOLTZITE, for follow-on operations, SportsFans, Unit 61398
Deep Panda is an advanced threat actor believed to have ties to Chinese state-sponsored activities. It operates under numerous aliases—Shell Crew, WebMasters, KungFu Kittens, PinkPanther, Black Vine, APT19, Winnti Group, Sandworm Team, among others—which has caused significant confusion in attribution efforts. The group's notable footprint began with the 2018 compromise of healthcare provider Anthem, where investigators identified spear‑phishing attachments and the installation of a web shell to maintain persistence. Subsequent analyses have linked similar tactics to other actors such as APT19 and Winnti Group, suggesting shared infrastructure or toolkits. Operationally, Deep Panda employs a variety of attack vectors including malicious Office macros (RTF/XLSM), PowerShell scripts, Windows Management Instrumentation queries, and web shells like China Chopper. Their campaigns show a clear emphasis on establishing footholds via publicly accessible hosting, then expanding lateral movement using SMB shares and WMI. The uncertainty surrounding the group’s exact identity stems from overlapping names, shared infrastructure, and differing industry reports, making precise attribution challenging yet highlighting the need for thorough monitoring of their broad threat landscape.
Targeted Sectors
Targeted Countries / Regions
Executive Summary
Deep Panda is a suspected Chinese espionage actor with a broad industry focus that includes government, finance, telecommunications, defense, healthcare and many other sectors. The group has been linked to high-profile intrusions such as the 2018 Anthem breach through spear‑phishing & web shell techniques. Their operations demonstrate long‑lasting persistence and multi‑stage campaigns aimed at gathering strategic and commercial intelligence.
Goals & Targeting
Deep Panda targets a diverse set of sectors with the primary objective of espionage—collecting strategic, technical, or commercial secrets. By focusing on governments, defense contractors, telecommunications firms, financial services, and healthcare providers, they aim to harvest sensitive policy documents, intellectual property, and proprietary data that can be leveraged for geopolitical advantage or economic gain. Their typical victims are organizations with high-value information: state agencies, critical infrastructure operators, major telecom operators, large financial institutions, and global defense contractors. The actor's choice of targets reflects an intent to gather intelligence across multiple domains to advance national interests in the cyber domain.
Enhanced Description
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
Deep Panda’s campaign lifecycle typically involves a prolonged initial compromise through spear‑phishing, followed by the deployment of web shells and PowerShell backdoors. They maintain long‑term persistence, often spanning months or years, and employ frequent lateral movement across networks via SMB shares and WMI. Victims are usually large enterprises or government institutions where valuable data resides; the actor selectively exfiltrates information relevant to national security or economic competition. Notable operations include the Anthem breach (2018) and suspected involvement in other incidents attributed to APT19 and Winnti, although attribution remains ambiguous due to overlapping tooling and infrastructure.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
The data are drawn from publicly available reports and analyses, many of which reference overlapping aliases (Deep Panda, APT19, Winnti). Because attribution is inconsistent across sources, there is uncertainty about whether all activities are performed by a single unit. Additionally, most public details date to 2017‑2018, so recent tactics or infrastructure could differ. Confidence in the core capabilities and target sectors remains high, but gaps exist regarding current operational tempo, tool evolution, and precise attribution.
No observed data linked yet.
40
Techniques
58
Tools
3
Campaigns
35
IOCs
0
Observed Data
11
Tactics