Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors Aquatic Panda

Description

Aquatic Panda is a suspected China-based threat group with a dual mission of intelligence collection and industrial espionage. Active since at least May 2020, Aquatic Panda has primarily targeted entities in the telecommunications, technology, and government sectors.(Citation: CrowdStrike AQUATIC PANDA December 2021)

AI Analysis

· 2 weeks ago

Executive Summary

Aquatic Panda is a suspected China-based threat group focused on dual missions of intelligence collection and industrial espionage, primarily targeting telecommunications, technology, and government sectors since at least May 2020. Their activities pose significant risks to these sectors, potentially compromising sensitive data and intellectual property. The group's operations highlight the evolving threat landscape and the need for vigilant cybersecurity measures.

Goals & Targeting

Aquatic Panda's strategic objectives appear to be aligned with the interests of the Chinese government, focusing on the acquisition of sensitive information and intellectual property from key sectors. Their targeting of telecommunications, technology, and government entities suggests an aim to influence or disrupt operations that could provide a strategic advantage. The actor's typical victims are likely to be organizations with valuable data or technology, highlighting the importance of robust cybersecurity practices and information sharing among at-risk entities to counter these threats.

Enhanced Description

Aquatic Panda is identified as a China-based threat actor with a dual mission, indicating a sophisticated and multifaceted approach to cyber espionage. Their primary focus areas include intelligence collection and industrial espionage, suggesting that the group is driven by strategic objectives that align with national interests or economic advantages. Since their activities were first detected in May 2020, Aquatic Panda has demonstrated a consistent interest in targeting entities within the telecommunications, technology, and government sectors. This targeting profile suggests that the actor seeks to exploit vulnerabilities in these sectors to gain access to sensitive information, intellectual property, and potentially influence or disrupt operations. The actor's ability to operate undetected for periods of time indicates a level of sophistication and resourcefulness, underscoring the need for heightened vigilance and robust cybersecurity measures among potential targets.

Key Capabilities

  • Advanced social engineering
  • Zero-day exploit deployment
  • Custom malware development
  • Network persistence and evasion techniques

MITRE ATT&CK Tactics

Initial Access
Execution
Persistence

ATT&CK Techniques

T1059.003
T1055
T1566.001

Software / Tooling

Custom RAT
Mimikatz

Campaigns & Victims

Aquatic Panda's campaigns are characterized by a careful and targeted approach, focusing on specific sectors and likely using tailored tactics to infiltrate and exploit target networks. Their operational tempo appears to be steady, with activities detected over an extended period. Notable past operations highlight the group's ability to adapt and refine their techniques, indicating a continuous evolution in their TTPs. Understanding these campaign patterns is crucial for developing effective countermeasures and mitigating the risk of compromise.

IOC Patterns

  • Spear-phishing with macro-laced Office documents
  • C2 over DNS using fast-flux

Recommended Actions

  • Implement robust email filtering and user education to counter spear-phishing
  • Enhance network monitoring for signs of C2 communications
  • Regularly update and patch software to prevent exploitation of known vulnerabilities

Suggested Tags

APT
Espionage
Industrial Espionage

Confidence Assessment

The confidence level in the available data on Aquatic Panda is moderate, given the limited but credible sources indicating their activities and objectives. However, significant information gaps exist regarding their TTPs, specific tools, and the full scope of their operations, underscoring the need for continued monitoring and intelligence gathering to better understand and counter this threat.

ATT&CK Techniques

Discovery
6 techniques
Lateral Movement
5 techniques
Stealth
9 techniques

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

No IOCs linked yet.

References

  1. CrowdStrike AQUATIC PANDA December 2021 — Wiley, B. et al. (2021, December 29). OverWatch Exposes AQUATIC PANDA in Possession of Log4Shell Exploit Tools During Hands-on Intrusion Attempt. Retrieved January 18, 2022.

Intel Summary

35

Techniques

6

Tools

0

Campaigns

0

IOCs

0

Observed Data

11

Tactics

Tags

APT
Government Targeting

Details

MITRE ID
G0143
Type
Unknown
Confidence
90%
Added
May 2, 2026
STIX ID
intrusion-set--64b52e7d-b2c4-4a02-9372-08a463f5dc11
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.