Turbine Panda, APT 26, Shell Crew, WebMasters, KungFu Kittens

Description

(RSA) During recent engagements, the RSA IR Team has responded to multiple incidents involving a common adversary targeting each client’s infrastructure and assets. The RSA IR Team is referring to this threat group internally as “Shell_Crew”; however, they are also referred to as Deep Panda, WebMasters, KungFu Kittens, SportsFans, and PinkPanther amongst the security community.

Some analysts track Turbine Panda, DarkHydrus, LazyMeerkat and APT 19, Deep Panda, C0d0so0 as the same group, but it is unclear from open source information if the groups are the same. Turbine Panda has some overlap with Emissary Panda, APT 27, LuckyMouse, Bronze Union.

Names

NameName-Giver
Turbine PandaCrowdStrike
APT 26Mandiant
Shell CrewRSA
WebMastersKaspersky
KungFu KittensFireEye
Group 13Talos
PinkPantherRSA
Black VineSymantec
Bronze ExpressSecureWorks
JerseyMikes?
Taffeta TyphoonMicrosoft

Country

State-sponsored, the Jiangsu Bureau of the MSS (JSSD/江苏省国家安全厅)

Motivation

  • Information theft and espionage
  • Financial crime

First Seen

2010

Observed Sectors

Observed Countries

Tools

Operations

Counter Operations

Information

Other Information

Uuid

442f4919-150b-4e0f-9867-1ebd78f54a9c

Last Card Change

2025-06-28