LiveActive security incident?Get immediate response
MITRE ATT&CK® Group

G0143: Aquatic Panda

Aquatic Panda is a suspected China-based threat group with a dual mission of intelligence collection and industrial espionage. Active since at least May 2020, Aquatic Panda has primarily targeted entities in the telecommunications, technology, and government sectors.CitationCrowdStrike AQUATIC PANDA December 2021

EnterpriseG0143GroupObject v2.0Modified
Glexia's Take · Automated analysis

Security context for executives and security teams

Automation confidenceMedium

Aquatic Panda matters because ATT&CK describes it as a suspected China-based group focused on intelligence collection and industrial espionage, primarily against telecommunications, technology, and government entities. For leaders, the practical issue is not the name of the group alone; it is whether the organization can detect and investigate hands-on intrusion behavior involving credential access, remote services, command execution, stealth, and local data collection across Windows and Unix-like environments referenced by the related techniques and tools.

Executive priority

Prioritize this as a resilience and sensitive-data protection use case if your organization operates in or supports telecommunications, technology, government, or similarly high-value environments. Executives should ask whether SOC, identity, endpoint, and incident response teams can prove coverage for credential theft from LSASS, domain account abuse, RDP/SMB/SSH lateral movement, PowerShell/cmd/Unix shell execution, WMI activity, log or history clearing, file deletion, and use of remote access tooling such as Cobalt Strike, Winnti variants, ShadowPad, and njRAT where relevant. The decision value is in validating evidence quality and response readiness, not assuming attribution from a single alert.

Technical view

ATT&CK provides no group-level detection text or explicit platforms for Aquatic Panda, so defenders should build validation around the related software and techniques. Coverage should be tested for Windows behaviors including LSASS access, PowerShell, Windows Command Shell, WMI, RDP, SMB/admin shares, Windows services/tasks, Wevtutil, and Windows RAT/backdoor tooling. Linux, macOS, ESXi, network device, and IaaS-relevant coverage should be reviewed where related techniques include SSH, Unix shell, command history clearing, file deletion, local data collection, and remote services. Detection engineering should emphasize behavior chains: valid account use followed by discovery, remote execution, credential access, data staging or collection, and cleanup/stealth actions.

Likely telemetry

  • Endpoint process creation and command-line telemetry from Windows, Linux, macOS, and ESXi where in scope
  • PowerShell logging, Windows Command Shell activity, and WMI execution records
  • Windows Security, RDP, SMB/admin share, service creation, scheduled task, and authentication logs
  • LSASS access signals, credential-dumping prevention or EDR events, and privileged process access telemetry
  • SSH authentication logs, shell history artifacts, Unix process execution, and file deletion events

Detection direction

  • Do not rely on group-name matching; validate detections against the ATT&CK-related behaviors and tools instead.
  • Correlate valid domain account use with unusual RDP, SMB, SSH, WMI, PowerShell, cmd, or Unix shell execution, especially across administrative boundaries.
  • Tune for false positives from legitimate administration by baselining admin tools, service management, WMI, PowerShell, SSH, and Wevtutil usage by role, host, and time window.
  • Review blind spots in command-line capture, PowerShell visibility, Linux/ESXi shell logging, Windows event retention, and endpoint coverage on servers and administrative workstations.
  • Treat cleanup behaviors such as command history clearing, file deletion, and log utility use as context-rich signals when paired with remote access, discovery, credential access, or data collection.

Mitigation priorities

  • First, harden identity controls around domain accounts, administrative privileges, and remote service access because multiple related techniques depend on valid account abuse and lateral movement.
  • Second, restrict and monitor RDP, SMB/admin shares, SSH, WMI, PowerShell, Windows Command Shell, and Unix shell use according to operational need.
  • Third, protect credential material by reducing unnecessary administrative rights and validating controls that limit or detect LSASS access.
  • Fourth, improve endpoint and server logging retention so cleanup attempts such as file deletion, command history clearing, or event log utility use do not erase the only evidence needed for response.
  • Fifth, maintain incident response playbooks that connect credential access, lateral movement, execution, collection, and stealth behaviors into one investigation path rather than isolated alerts.
Additional notes and limits

The supplied ATT&CK object identifies Aquatic Panda as a suspected China-based group active since at least May 2020 with a reported focus on intelligence collection and industrial espionage, primarily affecting telecommunications, technology, and government sectors. The relationship context is broad and includes several remote access tools and many techniques spanning execution, credential access, discovery, lateral movement, collection, and stealth. Use this as a threat-informed validation profile rather than a standalone attribution rule.

ATT&CK provides no official detection guidance, no group-level tactics, and no group-level platforms for this object. Platform references in this take come from related software and technique records, not from the group object itself. Local exposure depends on the organization’s sector, architecture, identity model, remote access patterns, and available telemetry. The supplied material does not support claims of current active exploitation or confirmed targeting of any specific organization.

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Official MITRE ATT&CK definition

Aquatic Panda

Aquatic Panda is a suspected China-based threat group with a dual mission of intelligence collection and industrial espionage. Active since at least May 2020, Aquatic Panda has primarily targeted entities in the telecommunications, technology, and government sectors.CitationCrowdStrike AQUATIC PANDA December 2021

View the same entry on attack.mitre.org (MITRE-hosted reference; in-page links above use the Glexia ATT&CK library.)

Glexia analysis

How security teams should use this page

Treat this object as behavior context, not an attribution claim. Validate the related groups, software, data sources, and mitigations against official ATT&CK relationships and your own telemetry before making control-coverage decisions.

Relationship explorer

All related ATT&CK context

No relationships are available in the current normalized data for this object.

Change history

Object version and sync metadata

The fields below describe the current mirrored snapshot. When Glexia retains multiple ATT&CK source imports, you can open the table to compare the same object across releases (hashes and MITRE timestamps). For MITRE’s own release notes and roadmap, see ATT&CK resources — Updates.

ATT&CK release
19.1
Object version
2.0
Created
Modified
Raw hash
43364e36184d756d...
Raw source

Mirrored ATT&CK source object

The raw object is retained through the mirrored ATT&CK source bundle and object hash. The raw endpoint returns the exact object from the mirrored bundle when available.

Source and licensing

Source: MITRE ATT&CK®. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation. Glexia is not affiliated with or endorsed by MITRE.