Aquatic Panda

Description

(CrowdStrike) AQUATIC PANDA is a China-based targeted intrusion adversary with a dual mission of intelligence collection and industrial espionage. It has likely operated since at least May 2020. AQUATIC PANDA operations have primarily focused on entities in the telecommunications, technology and government sectors. AQUATIC PANDA relies heavily on Cobalt Strike, and its toolset includes the unique Cobalt Strike downloader tracked as FishMaster. AQUATIC PANDA has also been observed delivering njRAT payloads to targets.

Names

NameName-Giver
Aquatic PandaCrowdStrike

Country

Motivation

  • Information theft and espionage

First Seen

2020

Observed Sectors

Tools

Information

Other Information

Uuid

0730437a-1b64-4777-a920-64bbe97214c0

Last Card Change

2022-01-25