LiveActive security incident?Get immediate response
MITRE ATT&CK® Group

G0143: Aquatic Panda

Aquatic Panda is a suspected China-based threat group with a dual mission of intelligence collection and industrial espionage. Active since at least May 2020, Aquatic Panda has primarily targeted entities in the telecommunications, technology, and government sectors.[1]

EnterpriseG0143GroupObject v2.0Modified
Glexia's Take · Automated analysis

Security context for executives and security teams

Automation confidenceMedium

Aquatic Panda matters because ATT&CK describes it as a suspected China-based group focused on intelligence collection and industrial espionage, primarily against telecommunications, technology, and government entities. For leaders, the practical issue is not the name of the group alone; it is whether the organization can detect and investigate hands-on intrusion behavior involving credential access, remote services, command execution, stealth, and local data collection across Windows and Unix-like environments referenced by the related techniques and tools.

Executive priority

Prioritize this as a resilience and sensitive-data protection use case if your organization operates in or supports telecommunications, technology, government, or similarly high-value environments. Executives should ask whether SOC, identity, endpoint, and incident response teams can prove coverage for credential theft from LSASS, domain account abuse, RDP/SMB/SSH lateral movement, PowerShell/cmd/Unix shell execution, WMI activity, log or history clearing, file deletion, and use of remote access tooling such as Cobalt Strike, Winnti variants, ShadowPad, and njRAT where relevant. The decision value is in validating evidence quality and response readiness, not assuming attribution from a single alert.

Technical view

ATT&CK provides no group-level detection text or explicit platforms for Aquatic Panda, so defenders should build validation around the related software and techniques. Coverage should be tested for Windows behaviors including LSASS access, PowerShell, Windows Command Shell, WMI, RDP, SMB/admin shares, Windows services/tasks, Wevtutil, and Windows RAT/backdoor tooling. Linux, macOS, ESXi, network device, and IaaS-relevant coverage should be reviewed where related techniques include SSH, Unix shell, command history clearing, file deletion, local data collection, and remote services. Detection engineering should emphasize behavior chains: valid account use followed by discovery, remote execution, credential access, data staging or collection, and cleanup/stealth actions.

Likely telemetry

  • Endpoint process creation and command-line telemetry from Windows, Linux, macOS, and ESXi where in scope
  • PowerShell logging, Windows Command Shell activity, and WMI execution records
  • Windows Security, RDP, SMB/admin share, service creation, scheduled task, and authentication logs
  • LSASS access signals, credential-dumping prevention or EDR events, and privileged process access telemetry
  • SSH authentication logs, shell history artifacts, Unix process execution, and file deletion events

Detection direction

  • Do not rely on group-name matching; validate detections against the ATT&CK-related behaviors and tools instead.
  • Correlate valid domain account use with unusual RDP, SMB, SSH, WMI, PowerShell, cmd, or Unix shell execution, especially across administrative boundaries.
  • Tune for false positives from legitimate administration by baselining admin tools, service management, WMI, PowerShell, SSH, and Wevtutil usage by role, host, and time window.
  • Review blind spots in command-line capture, PowerShell visibility, Linux/ESXi shell logging, Windows event retention, and endpoint coverage on servers and administrative workstations.
  • Treat cleanup behaviors such as command history clearing, file deletion, and log utility use as context-rich signals when paired with remote access, discovery, credential access, or data collection.

Mitigation priorities

  • First, harden identity controls around domain accounts, administrative privileges, and remote service access because multiple related techniques depend on valid account abuse and lateral movement.
  • Second, restrict and monitor RDP, SMB/admin shares, SSH, WMI, PowerShell, Windows Command Shell, and Unix shell use according to operational need.
  • Third, protect credential material by reducing unnecessary administrative rights and validating controls that limit or detect LSASS access.
  • Fourth, improve endpoint and server logging retention so cleanup attempts such as file deletion, command history clearing, or event log utility use do not erase the only evidence needed for response.
  • Fifth, maintain incident response playbooks that connect credential access, lateral movement, execution, collection, and stealth behaviors into one investigation path rather than isolated alerts.
Additional notes and limits

The supplied ATT&CK object identifies Aquatic Panda as a suspected China-based group active since at least May 2020 with a reported focus on intelligence collection and industrial espionage, primarily affecting telecommunications, technology, and government sectors. The relationship context is broad and includes several remote access tools and many techniques spanning execution, credential access, discovery, lateral movement, collection, and stealth. Use this as a threat-informed validation profile rather than a standalone attribution rule.

ATT&CK provides no official detection guidance, no group-level tactics, and no group-level platforms for this object. Platform references in this take come from related software and technique records, not from the group object itself. Local exposure depends on the organization’s sector, architecture, identity model, remote access patterns, and available telemetry. The supplied material does not support claims of current active exploitation or confirmed targeting of any specific organization.

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Official MITRE ATT&CK definition

Aquatic Panda

Aquatic Panda is a suspected China-based threat group with a dual mission of intelligence collection and industrial espionage. Active since at least May 2020, Aquatic Panda has primarily targeted entities in the telecommunications, technology, and government sectors.[1]

View the same entry on attack.mitre.org (MITRE-hosted reference; in-page links above use the Glexia ATT&CK library.)

Glexia analysis

How security teams should use this page

Treat this object as behavior context, not an attribution claim. Validate the related groups, software, data sources, and mitigations against official ATT&CK relationships and your own telemetry before making control-coverage decisions.

ATT&CK relationship table

Techniques used

This mirrors the MITRE pattern of making group, software, campaign, and technique relationships scannable. Relationship notes come from mirrored ATT&CK relationship text when available.

35 rows
DomainIDNameRelationship / procedure
EnterpriseT1027.010Command ObfuscationSub-technique

Aquatic Panda has encoded PowerShell commands in Base64.[1]

EnterpriseT1087Account Discovery

Aquatic Panda used the last command in Linux environments to identify recently logged-in users on victim machines.[2]

EnterpriseT1070.004File DeletionSub-technique

Aquatic Panda has deleted malicious executables from compromised machines.[1][2]

EnterpriseT1059.004Unix ShellSub-technique

Aquatic Panda used malicious shell scripts in Linux environments following access via SSH to install Linux versions of Winnti malware.[2]

EnterpriseT1021.002SMB/Windows Admin SharesSub-technique

Aquatic Panda used remote shares to enable lateral movement in victim environments.[2]

EnterpriseT1036.004Masquerade Task or ServiceSub-technique

Aquatic Panda created new, malicious services using names such as Windows User Service to attempt to blend in with legitimate items on victim systems.[2]

EnterpriseT1574.006Dynamic Linker HijackingSub-technique

Aquatic Panda modified the ld.so preload file in Linux environments to enable persistence for Winnti malware.[2]

EnterpriseT1070.003Clear Command HistorySub-technique

Aquatic Panda cleared command history in Linux environments to remove traces of activity after operations.[2]

EnterpriseT1543.003Windows ServiceSub-technique

Aquatic Panda created new Windows services for persistence that masqueraded as legitimate Windows services via name change.[2]

EnterpriseT1550.002Pass the HashSub-technique

Aquatic Panda used a registry edit to enable a Windows feature called RestrictedAdmin in victim environments. This change allowed Aquatic Panda to leverage "pass the hash" mechanisms as the alteration allows for RDP connections with a valid account name and hash only, without possessing a cleartext password value.[2]

EnterpriseT1574.001DLLSub-technique

Aquatic Panda has used DLL search-order hijacking to load `exe`, `dll`, and `dat` files into memory.[1] Aquatic Panda loaded a malicious DLL into the legitimate Windows Security Health Service executable (SecurityHealthService.exe) to execute malicious code on victim systems.[2]

EnterpriseT1021.001Remote Desktop ProtocolSub-technique

Aquatic Panda leveraged stolen credentials to move laterally via RDP in victim environments.[2]

EnterpriseT1005Data from Local System

Aquatic Panda captured local Windows security event log data from victim machines using the wevtutil utility to extract contents to an evtx output file.[2]

EnterpriseT1105Ingress Tool Transfer

Aquatic Panda has downloaded additional malware onto compromised hosts.[1]

EnterpriseT1007System Service Discovery

Aquatic Panda has attempted to discover services for third party EDR products.[1]

EnterpriseT1654Log Enumeration

Aquatic Panda enumerated logs related to authentication in Linux environments prior to deleting selective entries for defense evasion purposes.[2]

EnterpriseT1021.004SSHSub-technique

Aquatic Panda used SSH with captured user credentials to move laterally in victim environments.[2]

EnterpriseT1112Modify Registry

Aquatic Panda modified the victim registry to enable the `RestrictedAdmin` mode feature, allowing for pass the hash behaviors to function via RDP.[2]

EnterpriseT1036.005Match Legitimate Resource Name or LocationSub-technique

Aquatic Panda renamed or moved malicious binaries to legitimate locations to evade defenses and blend into victim environments.[2]

EnterpriseT1588.001MalwareSub-technique

Aquatic Panda has acquired and used njRAT in its operations.[1]

EnterpriseT1518.001Security Software DiscoverySub-technique

Aquatic Panda has attempted to discover third party endpoint detection and response (EDR) tools on compromised systems.[1]

EnterpriseT1059.003Windows Command ShellSub-technique

Aquatic Panda has attempted and failed to run Bash commands on a Windows host by passing them to cmd /C.[1]

EnterpriseT1685Disable or Modify Tools

Aquatic Panda has attempted to stop endpoint detection and response (EDR) tools on compromised systems.[1]

EnterpriseT1033System Owner/User Discovery

Aquatic Panda gathers information on recently logged-in users on victim devices.[2]

EnterpriseT1047Windows Management Instrumentation

Aquatic Panda used WMI for lateral movement in victim environments.[2]

EnterpriseT1588.002ToolSub-technique

Aquatic Panda has acquired and used Cobalt Strike in its operations.[1]

EnterpriseT1595.002Vulnerability ScanningSub-technique

Aquatic Panda has used publicly accessible DNS logging services to identify servers vulnerable to Log4j (CVE 2021-44228).[1]

EnterpriseT1003.001LSASS MemorySub-technique

Aquatic Panda has attempted to harvest credentials through LSASS memory dumping.[1]

EnterpriseT1021Remote Services

Aquatic Panda used remote scheduled tasks to install malicious software on victim systems during lateral movement actions.[2]

EnterpriseT1082System Information Discovery

Aquatic Panda has used native OS commands to understand privilege levels and system details.[1]

EnterpriseT1218.011Rundll32Sub-technique

Aquatic Panda used rundll32.exe to proxy execution of a malicious DLL file identified as a keylogging binary.[2]

EnterpriseT1685.005Clear Windows Event LogsSub-technique

Aquatic Panda clears Windows Event Logs following activity to evade defenses.[2]

EnterpriseT1078.002Domain AccountsSub-technique

Aquatic Panda used multiple mechanisms to capture valid user accounts for victim domains to enable lateral movement and access to additional hosts in victim environments.[2]

EnterpriseT1560.001Archive via UtilitySub-technique

Aquatic Panda has used several publicly available tools, including WinRAR and 7zip, to compress collected files and memory dumps prior to exfiltration.[1][2]

EnterpriseT1059.001PowerShellSub-technique

Aquatic Panda has downloaded additional scripts and executed Base64 encoded commands in PowerShell.[1]

Associated objects

Groups, software, and campaigns

ToolEnterprise

S0645: Wevtutil

Wevtutil is a Windows command-line utility that enables administrators to retrieve information about event logs and publishers.[1]

Windows
MalwareEnterprise

S0385: njRAT

njRAT is a remote access tool (RAT) that was first observed in 2012. It has been used by threat actors in the Middle East.[1]

Windows
MalwareEnterprise

S0154: Cobalt Strike

Cobalt Strike is a commercial, full-featured, remote access tool that bills itself as “adversary simulation software designed to execute targeted attacks and emulate the post-exploitation actions of advanced threat actors”. Cobalt Strike’s interactive post-exploit capabilities cover the full range of ATT&CK tactics, all executed within a single, integrated system.[1]

In addition to its own capabilities, Cobalt Strike leverages the capabilities of other well-known tools such as Metasploit and Mimikatz.[1]

LinuxmacOSWindows
MalwareEnterprise

S0596: ShadowPad

ShadowPad is a modular backdoor that was first identified in a supply chain compromise of the NetSarang software in mid-July 2017. The malware was originally thought to be exclusively used by APT41, but has since been observed to be used by various Chinese threat activity groups. [1][2][3]

Windows
Relationship explorer

All related ATT&CK context

Change history

Object version and sync metadata

The fields below describe the current mirrored snapshot. When Glexia retains multiple ATT&CK source imports, you can open the table to compare the same object across releases (hashes and MITRE timestamps). For MITRE’s own release notes and roadmap, see ATT&CK resources — Updates.

ATT&CK release
19.1
Object version
2.0
Created
Modified
Raw hash
43364e36184d756d...
Imported snapshots across ATT&CK releases(1)
ReleaseBundle importedObject versionModifiedStatusRaw hash
19.12.0Current bundle43364e36184d…
Raw source

Mirrored ATT&CK source object

The raw object is retained through the mirrored ATT&CK source bundle and object hash. The raw endpoint returns the exact object from the mirrored bundle when available.

Source references

External references and citations

MITRE external references are preserved separately from Glexia analysis so citations remain traceable to their original source records.

  1. [1]
    CrowdStrike AQUATIC PANDA December 2021

    Wiley, B. et al. (2021, December 29). OverWatch Exposes AQUATIC PANDA in Possession of Log4Shell Exploit Tools During Hands-on Intrusion Attempt. Retrieved January 18, 2022.

    Open source URL
  2. [2]
    Crowdstrike HuntReport 2022

    CrowdStrike. (2023). 2022 Falcon OverWatch Threat Hunting Report. Retrieved May 20, 2024.

    Open source URL
  3. [3]
    CrowdStrike AQUATIC PANDA December 2021

    Wiley, B. et al. (2021, December 29). OverWatch Exposes AQUATIC PANDA in Possession of Log4Shell Exploit Tools During Hands-on Intrusion Attempt. Retrieved January 18, 2022.

    Open source URL
  4. [4]
    CrowdStrike AQUATIC PANDA December 2021

    Wiley, B. et al. (2021, December 29). OverWatch Exposes AQUATIC PANDA in Possession of Log4Shell Exploit Tools During Hands-on Intrusion Attempt. Retrieved January 18, 2022.

    Open source URL
  5. [5]
    mitre-attackG0143
    Open source URL
  6. [6]
    mitre-attackG0143
    Open source URL
  7. [7]
    mitre-attackG0143
    Open source URL
  8. [8]
    CrowdStrike AQUATIC PANDA December 2021

    Wiley, B. et al. (2021, December 29). OverWatch Exposes AQUATIC PANDA in Possession of Log4Shell Exploit Tools During Hands-on Intrusion Attempt. Retrieved January 18, 2022.

    Open source URL
  9. [9]
    CrowdStrike AQUATIC PANDA December 2021

    Wiley, B. et al. (2021, December 29). OverWatch Exposes AQUATIC PANDA in Possession of Log4Shell Exploit Tools During Hands-on Intrusion Attempt. Retrieved January 18, 2022.

    Open source URL
  10. [10]
    Crowdstrike HuntReport 2022

    CrowdStrike. (2023). 2022 Falcon OverWatch Threat Hunting Report. Retrieved May 20, 2024.

    Open source URL
  11. [11]
    CrowdStrike AQUATIC PANDA December 2021

    Wiley, B. et al. (2021, December 29). OverWatch Exposes AQUATIC PANDA in Possession of Log4Shell Exploit Tools During Hands-on Intrusion Attempt. Retrieved January 18, 2022.

    Open source URL
  12. [12]
    CrowdStrike AQUATIC PANDA December 2021

    Wiley, B. et al. (2021, December 29). OverWatch Exposes AQUATIC PANDA in Possession of Log4Shell Exploit Tools During Hands-on Intrusion Attempt. Retrieved January 18, 2022.

    Open source URL
  13. [13]
    Crowdstrike HuntReport 2022

    CrowdStrike. (2023). 2022 Falcon OverWatch Threat Hunting Report. Retrieved May 20, 2024.

    Open source URL
  14. [14]
    Crowdstrike HuntReport 2022

    CrowdStrike. (2023). 2022 Falcon OverWatch Threat Hunting Report. Retrieved May 20, 2024.

    Open source URL
  15. [15]
    Crowdstrike HuntReport 2022

    CrowdStrike. (2023). 2022 Falcon OverWatch Threat Hunting Report. Retrieved May 20, 2024.

    Open source URL
  16. [16]
    Crowdstrike HuntReport 2022

    CrowdStrike. (2023). 2022 Falcon OverWatch Threat Hunting Report. Retrieved May 20, 2024.

    Open source URL
  17. [17]
    Crowdstrike HuntReport 2022

    CrowdStrike. (2023). 2022 Falcon OverWatch Threat Hunting Report. Retrieved May 20, 2024.

    Open source URL
  18. [18]
    Crowdstrike HuntReport 2022

    CrowdStrike. (2023). 2022 Falcon OverWatch Threat Hunting Report. Retrieved May 20, 2024.

    Open source URL
  19. [19]
    Crowdstrike HuntReport 2022

    CrowdStrike. (2023). 2022 Falcon OverWatch Threat Hunting Report. Retrieved May 20, 2024.

    Open source URL
  20. [20]
    Crowdstrike HuntReport 2022

    CrowdStrike. (2023). 2022 Falcon OverWatch Threat Hunting Report. Retrieved May 20, 2024.

    Open source URL
  21. [21]
    Crowdstrike HuntReport 2022

    CrowdStrike. (2023). 2022 Falcon OverWatch Threat Hunting Report. Retrieved May 20, 2024.

    Open source URL
  22. [22]
    Crowdstrike HuntReport 2022

    CrowdStrike. (2023). 2022 Falcon OverWatch Threat Hunting Report. Retrieved May 20, 2024.

    Open source URL
  23. [23]
    Crowdstrike HuntReport 2022

    CrowdStrike. (2023). 2022 Falcon OverWatch Threat Hunting Report. Retrieved May 20, 2024.

    Open source URL
  24. [24]
    Crowdstrike HuntReport 2022

    CrowdStrike. (2023). 2022 Falcon OverWatch Threat Hunting Report. Retrieved May 20, 2024.

    Open source URL
  25. [25]
    Crowdstrike HuntReport 2022

    CrowdStrike. (2023). 2022 Falcon OverWatch Threat Hunting Report. Retrieved May 20, 2024.

    Open source URL
  26. [26]
    Crowdstrike HuntReport 2022

    CrowdStrike. (2023). 2022 Falcon OverWatch Threat Hunting Report. Retrieved May 20, 2024.

    Open source URL
  27. [27]
    Crowdstrike HuntReport 2022

    CrowdStrike. (2023). 2022 Falcon OverWatch Threat Hunting Report. Retrieved May 20, 2024.

    Open source URL
  28. [28]
    Crowdstrike HuntReport 2022

    CrowdStrike. (2023). 2022 Falcon OverWatch Threat Hunting Report. Retrieved May 20, 2024.

    Open source URL
  29. [29]
    Crowdstrike HuntReport 2022

    CrowdStrike. (2023). 2022 Falcon OverWatch Threat Hunting Report. Retrieved May 20, 2024.

    Open source URL
  30. [30]
    Crowdstrike HuntReport 2022

    CrowdStrike. (2023). 2022 Falcon OverWatch Threat Hunting Report. Retrieved May 20, 2024.

    Open source URL
  31. [31]
    CrowdStrike AQUATIC PANDA December 2021

    Wiley, B. et al. (2021, December 29). OverWatch Exposes AQUATIC PANDA in Possession of Log4Shell Exploit Tools During Hands-on Intrusion Attempt. Retrieved January 18, 2022.

    Open source URL
  32. [32]
    CrowdStrike AQUATIC PANDA December 2021

    Wiley, B. et al. (2021, December 29). OverWatch Exposes AQUATIC PANDA in Possession of Log4Shell Exploit Tools During Hands-on Intrusion Attempt. Retrieved January 18, 2022.

    Open source URL
  33. [33]
    Crowdstrike HuntReport 2022

    CrowdStrike. (2023). 2022 Falcon OverWatch Threat Hunting Report. Retrieved May 20, 2024.

    Open source URL
  34. [34]
    Crowdstrike HuntReport 2022

    CrowdStrike. (2023). 2022 Falcon OverWatch Threat Hunting Report. Retrieved May 20, 2024.

    Open source URL
  35. [35]
    Crowdstrike HuntReport 2022

    CrowdStrike. (2023). 2022 Falcon OverWatch Threat Hunting Report. Retrieved May 20, 2024.

    Open source URL
  36. [36]
    Crowdstrike HuntReport 2022

    CrowdStrike. (2023). 2022 Falcon OverWatch Threat Hunting Report. Retrieved May 20, 2024.

    Open source URL
  37. [37]
    Crowdstrike HuntReport 2022

    CrowdStrike. (2023). 2022 Falcon OverWatch Threat Hunting Report. Retrieved May 20, 2024.

    Open source URL
  38. [38]
    Crowdstrike HuntReport 2022

    CrowdStrike. (2023). 2022 Falcon OverWatch Threat Hunting Report. Retrieved May 20, 2024.

    Open source URL
  39. [39]
    Crowdstrike HuntReport 2022

    CrowdStrike. (2023). 2022 Falcon OverWatch Threat Hunting Report. Retrieved May 20, 2024.

    Open source URL
  40. [40]
    Crowdstrike HuntReport 2022

    CrowdStrike. (2023). 2022 Falcon OverWatch Threat Hunting Report. Retrieved May 20, 2024.

    Open source URL
  41. [41]
    CrowdStrike AQUATIC PANDA December 2021

    Wiley, B. et al. (2021, December 29). OverWatch Exposes AQUATIC PANDA in Possession of Log4Shell Exploit Tools During Hands-on Intrusion Attempt. Retrieved January 18, 2022.

    Open source URL
  42. [42]
    CrowdStrike AQUATIC PANDA December 2021

    Wiley, B. et al. (2021, December 29). OverWatch Exposes AQUATIC PANDA in Possession of Log4Shell Exploit Tools During Hands-on Intrusion Attempt. Retrieved January 18, 2022.

    Open source URL
  43. [43]
    CrowdStrike AQUATIC PANDA December 2021

    Wiley, B. et al. (2021, December 29). OverWatch Exposes AQUATIC PANDA in Possession of Log4Shell Exploit Tools During Hands-on Intrusion Attempt. Retrieved January 18, 2022.

    Open source URL
  44. [44]
    CrowdStrike AQUATIC PANDA December 2021

    Wiley, B. et al. (2021, December 29). OverWatch Exposes AQUATIC PANDA in Possession of Log4Shell Exploit Tools During Hands-on Intrusion Attempt. Retrieved January 18, 2022.

    Open source URL
  45. [45]
    Crowdstrike HuntReport 2022

    CrowdStrike. (2023). 2022 Falcon OverWatch Threat Hunting Report. Retrieved May 20, 2024.

    Open source URL
  46. [46]
    Crowdstrike HuntReport 2022

    CrowdStrike. (2023). 2022 Falcon OverWatch Threat Hunting Report. Retrieved May 20, 2024.

    Open source URL
  47. [47]
    Crowdstrike HuntReport 2022

    CrowdStrike. (2023). 2022 Falcon OverWatch Threat Hunting Report. Retrieved May 20, 2024.

    Open source URL
  48. [48]
    Crowdstrike HuntReport 2022

    CrowdStrike. (2023). 2022 Falcon OverWatch Threat Hunting Report. Retrieved May 20, 2024.

    Open source URL
  49. [49]
    Crowdstrike HuntReport 2022

    CrowdStrike. (2023). 2022 Falcon OverWatch Threat Hunting Report. Retrieved May 20, 2024.

    Open source URL
  50. [50]
    Crowdstrike HuntReport 2022

    CrowdStrike. (2023). 2022 Falcon OverWatch Threat Hunting Report. Retrieved May 20, 2024.

    Open source URL
  51. [51]
    Crowdstrike HuntReport 2022

    CrowdStrike. (2023). 2022 Falcon OverWatch Threat Hunting Report. Retrieved May 20, 2024.

    Open source URL
  52. [52]
    Crowdstrike HuntReport 2022

    CrowdStrike. (2023). 2022 Falcon OverWatch Threat Hunting Report. Retrieved May 20, 2024.

    Open source URL
  53. [53]
    CrowdStrike AQUATIC PANDA December 2021

    Wiley, B. et al. (2021, December 29). OverWatch Exposes AQUATIC PANDA in Possession of Log4Shell Exploit Tools During Hands-on Intrusion Attempt. Retrieved January 18, 2022.

    Open source URL
  54. [54]
    CrowdStrike AQUATIC PANDA December 2021

    Wiley, B. et al. (2021, December 29). OverWatch Exposes AQUATIC PANDA in Possession of Log4Shell Exploit Tools During Hands-on Intrusion Attempt. Retrieved January 18, 2022.

    Open source URL
  55. [55]
    CrowdStrike AQUATIC PANDA December 2021

    Wiley, B. et al. (2021, December 29). OverWatch Exposes AQUATIC PANDA in Possession of Log4Shell Exploit Tools During Hands-on Intrusion Attempt. Retrieved January 18, 2022.

    Open source URL
  56. [56]
    CrowdStrike AQUATIC PANDA December 2021

    Wiley, B. et al. (2021, December 29). OverWatch Exposes AQUATIC PANDA in Possession of Log4Shell Exploit Tools During Hands-on Intrusion Attempt. Retrieved January 18, 2022.

    Open source URL
  57. [57]
    CrowdStrike AQUATIC PANDA December 2021

    Wiley, B. et al. (2021, December 29). OverWatch Exposes AQUATIC PANDA in Possession of Log4Shell Exploit Tools During Hands-on Intrusion Attempt. Retrieved January 18, 2022.

    Open source URL
  58. [58]
    CrowdStrike AQUATIC PANDA December 2021

    Wiley, B. et al. (2021, December 29). OverWatch Exposes AQUATIC PANDA in Possession of Log4Shell Exploit Tools During Hands-on Intrusion Attempt. Retrieved January 18, 2022.

    Open source URL
  59. [59]
    CrowdStrike AQUATIC PANDA December 2021

    Wiley, B. et al. (2021, December 29). OverWatch Exposes AQUATIC PANDA in Possession of Log4Shell Exploit Tools During Hands-on Intrusion Attempt. Retrieved January 18, 2022.

    Open source URL
  60. [60]
    CrowdStrike AQUATIC PANDA December 2021

    Wiley, B. et al. (2021, December 29). OverWatch Exposes AQUATIC PANDA in Possession of Log4Shell Exploit Tools During Hands-on Intrusion Attempt. Retrieved January 18, 2022.

    Open source URL
  61. [61]
    Crowdstrike HuntReport 2022

    CrowdStrike. (2023). 2022 Falcon OverWatch Threat Hunting Report. Retrieved May 20, 2024.

    Open source URL
  62. [62]
    Crowdstrike HuntReport 2022

    CrowdStrike. (2023). 2022 Falcon OverWatch Threat Hunting Report. Retrieved May 20, 2024.

    Open source URL
  63. [63]
    Crowdstrike HuntReport 2022

    CrowdStrike. (2023). 2022 Falcon OverWatch Threat Hunting Report. Retrieved May 20, 2024.

    Open source URL
  64. [64]
    Crowdstrike HuntReport 2022

    CrowdStrike. (2023). 2022 Falcon OverWatch Threat Hunting Report. Retrieved May 20, 2024.

    Open source URL
  65. [65]
    CrowdStrike AQUATIC PANDA December 2021

    Wiley, B. et al. (2021, December 29). OverWatch Exposes AQUATIC PANDA in Possession of Log4Shell Exploit Tools During Hands-on Intrusion Attempt. Retrieved January 18, 2022.

    Open source URL
  66. [66]
    CrowdStrike AQUATIC PANDA December 2021

    Wiley, B. et al. (2021, December 29). OverWatch Exposes AQUATIC PANDA in Possession of Log4Shell Exploit Tools During Hands-on Intrusion Attempt. Retrieved January 18, 2022.

    Open source URL
  67. [67]
    CrowdStrike AQUATIC PANDA December 2021

    Wiley, B. et al. (2021, December 29). OverWatch Exposes AQUATIC PANDA in Possession of Log4Shell Exploit Tools During Hands-on Intrusion Attempt. Retrieved January 18, 2022.

    Open source URL
  68. [68]
    CrowdStrike AQUATIC PANDA December 2021

    Wiley, B. et al. (2021, December 29). OverWatch Exposes AQUATIC PANDA in Possession of Log4Shell Exploit Tools During Hands-on Intrusion Attempt. Retrieved January 18, 2022.

    Open source URL
  69. [69]
    CrowdStrike AQUATIC PANDA December 2021

    Wiley, B. et al. (2021, December 29). OverWatch Exposes AQUATIC PANDA in Possession of Log4Shell Exploit Tools During Hands-on Intrusion Attempt. Retrieved January 18, 2022.

    Open source URL
  70. [70]
    CrowdStrike AQUATIC PANDA December 2021

    Wiley, B. et al. (2021, December 29). OverWatch Exposes AQUATIC PANDA in Possession of Log4Shell Exploit Tools During Hands-on Intrusion Attempt. Retrieved January 18, 2022.

    Open source URL
  71. [71]
    CrowdStrike AQUATIC PANDA December 2021

    Wiley, B. et al. (2021, December 29). OverWatch Exposes AQUATIC PANDA in Possession of Log4Shell Exploit Tools During Hands-on Intrusion Attempt. Retrieved January 18, 2022.

    Open source URL
  72. [72]
    CrowdStrike AQUATIC PANDA December 2021

    Wiley, B. et al. (2021, December 29). OverWatch Exposes AQUATIC PANDA in Possession of Log4Shell Exploit Tools During Hands-on Intrusion Attempt. Retrieved January 18, 2022.

    Open source URL
  73. [73]
    Crowdstrike HuntReport 2022

    CrowdStrike. (2023). 2022 Falcon OverWatch Threat Hunting Report. Retrieved May 20, 2024.

    Open source URL
  74. [74]
    Crowdstrike HuntReport 2022

    CrowdStrike. (2023). 2022 Falcon OverWatch Threat Hunting Report. Retrieved May 20, 2024.

    Open source URL
  75. [75]
    CrowdStrike AQUATIC PANDA December 2021

    Wiley, B. et al. (2021, December 29). OverWatch Exposes AQUATIC PANDA in Possession of Log4Shell Exploit Tools During Hands-on Intrusion Attempt. Retrieved January 18, 2022.

    Open source URL
  76. [76]
    CrowdStrike AQUATIC PANDA December 2021

    Wiley, B. et al. (2021, December 29). OverWatch Exposes AQUATIC PANDA in Possession of Log4Shell Exploit Tools During Hands-on Intrusion Attempt. Retrieved January 18, 2022.

    Open source URL
  77. [77]
    Crowdstrike HuntReport 2022

    CrowdStrike. (2023). 2022 Falcon OverWatch Threat Hunting Report. Retrieved May 20, 2024.

    Open source URL
  78. [78]
    Crowdstrike HuntReport 2022

    CrowdStrike. (2023). 2022 Falcon OverWatch Threat Hunting Report. Retrieved May 20, 2024.

    Open source URL
  79. [79]
    CrowdStrike AQUATIC PANDA December 2021

    Wiley, B. et al. (2021, December 29). OverWatch Exposes AQUATIC PANDA in Possession of Log4Shell Exploit Tools During Hands-on Intrusion Attempt. Retrieved January 18, 2022.

    Open source URL
  80. [80]
    CrowdStrike AQUATIC PANDA December 2021

    Wiley, B. et al. (2021, December 29). OverWatch Exposes AQUATIC PANDA in Possession of Log4Shell Exploit Tools During Hands-on Intrusion Attempt. Retrieved January 18, 2022.

    Open source URL
  81. [81]
    Crowdstrike HuntReport 2022

    CrowdStrike. (2023). 2022 Falcon OverWatch Threat Hunting Report. Retrieved May 20, 2024.

    Open source URL
  82. [82]
    Crowdstrike HuntReport 2022

    CrowdStrike. (2023). 2022 Falcon OverWatch Threat Hunting Report. Retrieved May 20, 2024.

    Open source URL
  83. [83]
    Crowdstrike HuntReport 2022

    CrowdStrike. (2023). 2022 Falcon OverWatch Threat Hunting Report. Retrieved May 20, 2024.

    Open source URL
  84. [84]
    CrowdStrike AQUATIC PANDA December 2021

    Wiley, B. et al. (2021, December 29). OverWatch Exposes AQUATIC PANDA in Possession of Log4Shell Exploit Tools During Hands-on Intrusion Attempt. Retrieved January 18, 2022.

    Open source URL
  85. [85]
    Crowdstrike HuntReport 2022

    CrowdStrike. (2023). 2022 Falcon OverWatch Threat Hunting Report. Retrieved May 20, 2024.

    Open source URL
  86. [86]
    CrowdStrike AQUATIC PANDA December 2021

    Wiley, B. et al. (2021, December 29). OverWatch Exposes AQUATIC PANDA in Possession of Log4Shell Exploit Tools During Hands-on Intrusion Attempt. Retrieved January 18, 2022.

    Open source URL
  87. [87]
    Crowdstrike HuntReport 2022

    CrowdStrike. (2023). 2022 Falcon OverWatch Threat Hunting Report. Retrieved May 20, 2024.

    Open source URL
Source and licensing

Source: MITRE ATT&CK®. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation. Glexia is not affiliated with or endorsed by MITRE.