THREAT_ACTOR · G0143
Aquatic Panda
Also known as: Aquatic Panda
Profile
Aquatic Panda is a suspected China-based threat group with a dual mission of intelligence collection and industrial espionage. Active since at least May 2020, Aquatic Panda has primarily targeted entities in the telecommunications, technology, and government sectors.
MITRE ATT&CK ↗Techniques
35 ATT&CK techniques attributed to this actor.
T1003.001 LSASS MemoryT1005 Data from Local SystemT1007 System Service DiscoveryT1021 Remote ServicesT1021.001 Remote Desktop ProtocolT1021.002 SMB/Windows Admin SharesT1021.004 SSHT1027.010 Command ObfuscationT1033 System Owner/User DiscoveryT1036.004 Masquerade Task or ServiceT1036.005 Match Legitimate Resource Name or LocationT1047 Windows Management InstrumentationT1059.001 PowerShellT1059.003 Windows Command ShellT1059.004 Unix ShellT1070.003 Clear Command HistoryT1070.004 File DeletionT1078.002 Domain AccountsT1082 System Information DiscoveryT1087 Account DiscoveryT1105 Ingress Tool TransferT1112 Modify RegistryT1218.011 Rundll32T1518.001 Security Software DiscoveryT1543.003 Windows ServiceT1550.002 Pass the HashT1560.001 Archive via UtilityT1574.001 DLLT1574.006 Dynamic Linker HijackingT1588.001 MalwareT1588.002 ToolT1595.002 Vulnerability ScanningT1654 Log EnumerationT1685 Disable or Modify ToolsT1685.005 Clear Windows Event Logs
Software
6 malware/tools attributed to this actor.
Winnti for WindowsCobalt StrikenjRATWinnti for LinuxShadowPadWevtutil
Related corpus activity
9,512 indicators EXHIBIT techniques this actor uses. This is a shared-technique signal, not a first-party attribution to Aquatic Panda.
| Indicator | Type | Family | Sev | Src |
|---|---|---|---|---|
| cve-2026-3102 | cve | — | 85 | 3 |
| cve-2026-1969 | cve | — | 85 | 1 |
| cve-2025-11837 | cve | — | 85 | 2 |
| cve-2014-2321 | cve | — | 85 | 1 |
| cve-2025-34117 | cve | — | 85 | 1 |
| cve-2021-29441 | cve | — | 85 | 1 |
| cve-2026-22584 | cve | — | 85 | 2 |
| cve-2013-3307 | cve | — | 85 | 2 |
| cve-2016-15047 | cve | — | 85 | 4 |
| cve-2018-8007 | cve | — | 85 | 1 |
| cve-2020-17456 | cve | — | 85 | 1 |
| cve-2025-2492 | cve | — | 85 | 2 |
| cve-2017-18377 | cve | — | 85 | 1 |
| cve-2021-25646 | cve | — | 85 | 1 |
| cve-2025-66478 | cve | — | 85 | 2 |
| cve-2025-0921 | cve | — | 85 | 2 |
| cve-2016-5681 | cve | — | 85 | 2 |
| cve-2021-27076 | cve | — | 85 | 1 |
| cve-2025-68670 | cve | — | 85 | 2 |
| cve-2022-47945 | cve | — | 85 | 1 |
| cve-2025-34054 | cve | — | 85 | 4 |
| cve-2024-1781 | cve | — | 85 | 1 |
| cve-2023-44976 | cve | ransomware | 85 | 2 |
| cve-2021-4045 | cve | — | 85 | 1 |
| cve-2020-22653 | cve | — | 85 | 2 |
| cve-2020-22658 | cve | — | 85 | 2 |
| cve-2026-4368 | cve | ransomware | 85 | 1 |
| cve-2025-23304 | cve | — | 85 | 2 |
| cve-2013-7471 | cve | — | 85 | 1 |
| cve-2026-0740 | cve | — | 85 | 1 |
Showing the top 30 by severity of 9,512.