G0143: Aquatic Panda
Aquatic Panda is a suspected China-based threat group with a dual mission of intelligence collection and industrial espionage. Active since at least May 2020, Aquatic Panda has primarily targeted entities in the telecommunications, technology, and government sectors.[1]
Security context for executives and security teams
G0143: Aquatic Panda describes [Aquatic Panda](https://attack.mitre.org/groups/G0143) is a suspected China-based threat group with a dual mission of intelligence collection and industrial espionage. Active since at least May 2020, [Aquatic Panda](https://attack.mitre.org/groups/G0143) has primarily targeted entities in the telecommunications, technology, and government sectors.(Citation: CrowdStrike AQUATIC PANDA December 2021)
Executive priority
G0143: Aquatic Panda is an official MITRE ATT&CK group. Glexia treats it as defensive behavior context for prioritizing monitoring, control validation, and response planning without using the object by itself as an attribution claim.
Technical view
Security teams should validate G0143: Aquatic Panda by reviewing the official ATT&CK relationships, mapped tactics (the mapped ATT&CK tactic context), supported platforms (the platforms named in the official object), and available local telemetry before making detection or mitigation decisions.
Likely telemetry
- Official ATT&CK relationships and object metadata
Detection direction
- Validate whether G0143: Aquatic Panda appears in your detection coverage and tabletop scenarios.
- Use the object to align executive risk language with SOC, incident response, and detection engineering work.
- Do not treat ATT&CK relationship context as attribution without corroborating evidence.
Mitigation priorities
- Map the object to existing controls and identify missing telemetry or response ownership.
- Prioritize mitigations that reduce exposure on the listed platforms and tactics.
- Review adjacent ATT&CK relationships before changing policy, detections, or reporting language.
Additional notes and limits
Baseline Glexia take generated from the official MITRE ATT&CK STIX object, source hash, tactics, platforms, and detection fields. It is safe to replace with a richer model-generated take for the same source hash later.
This baseline take is source-grounded and schema-validated, but it does not include environment-specific telemetry, incident evidence, or threat-intelligence corroboration.
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
Aquatic Panda
Aquatic Panda is a suspected China-based threat group with a dual mission of intelligence collection and industrial espionage. Active since at least May 2020, Aquatic Panda has primarily targeted entities in the telecommunications, technology, and government sectors.[1]
How security teams should use this page
Treat this object as behavior context, not an attribution claim. Validate the related groups, software, data sources, and mitigations against official ATT&CK relationships and your own telemetry before making control-coverage decisions.
Techniques used
This mirrors the MITRE pattern of making group, software, campaign, and technique relationships scannable. Relationship notes come from mirrored ATT&CK relationship text when available.
| Domain | ID | Name | Relationship / procedure |
|---|---|---|---|
| Enterprise | T1027.010 | Command ObfuscationSub-technique | Aquatic Panda has encoded PowerShell commands in Base64.[1] |
| Enterprise | T1087 | Account Discovery | Aquatic Panda used the |
| Enterprise | T1070.004 | File DeletionSub-technique | Aquatic Panda has deleted malicious executables from compromised machines.[1]CitationCrowdstrike HuntReport 2022 |
| Enterprise | T1059.004 | Unix ShellSub-technique | Aquatic Panda used malicious shell scripts in Linux environments following access via SSH to install Linux versions of Winnti malware.CitationCrowdstrike HuntReport 2022 |
| Enterprise | T1021.002 | SMB/Windows Admin SharesSub-technique | Aquatic Panda used remote shares to enable lateral movement in victim environments.CitationCrowdstrike HuntReport 2022 |
| Enterprise | T1036.004 | Masquerade Task or ServiceSub-technique | Aquatic Panda created new, malicious services using names such as |
| Enterprise | T1574.006 | Dynamic Linker HijackingSub-technique | Aquatic Panda modified the |
| Enterprise | T1070.003 | Clear Command HistorySub-technique | Aquatic Panda cleared command history in Linux environments to remove traces of activity after operations.CitationCrowdstrike HuntReport 2022 |
| Enterprise | T1543.003 | Windows ServiceSub-technique | Aquatic Panda created new Windows services for persistence that masqueraded as legitimate Windows services via name change.CitationCrowdstrike HuntReport 2022 |
| Enterprise | T1550.002 | Pass the HashSub-technique | Aquatic Panda used a registry edit to enable a Windows feature called |
| Enterprise | T1574.001 | DLLSub-technique | Aquatic Panda has used DLL search-order hijacking to load `exe`, `dll`, and `dat` files into memory.[1] Aquatic Panda loaded a malicious DLL into the legitimate Windows Security Health Service executable ( |
| Enterprise | T1021.001 | Remote Desktop ProtocolSub-technique | Aquatic Panda leveraged stolen credentials to move laterally via RDP in victim environments.CitationCrowdstrike HuntReport 2022 |
| Enterprise | T1005 | Data from Local System | Aquatic Panda captured local Windows security event log data from victim machines using the |
| Enterprise | T1105 | Ingress Tool Transfer | Aquatic Panda has downloaded additional malware onto compromised hosts.[1] |
| Enterprise | T1007 | System Service Discovery | Aquatic Panda has attempted to discover services for third party EDR products.[1] |
| Enterprise | T1654 | Log Enumeration | Aquatic Panda enumerated logs related to authentication in Linux environments prior to deleting selective entries for defense evasion purposes.CitationCrowdstrike HuntReport 2022 |
| Enterprise | T1021.004 | SSHSub-technique | Aquatic Panda used SSH with captured user credentials to move laterally in victim environments.CitationCrowdstrike HuntReport 2022 |
| Enterprise | T1112 | Modify Registry | Aquatic Panda modified the victim registry to enable the `RestrictedAdmin` mode feature, allowing for pass the hash behaviors to function via RDP.CitationCrowdstrike HuntReport 2022 |
| Enterprise | T1036.005 | Match Legitimate Resource Name or LocationSub-technique | Aquatic Panda renamed or moved malicious binaries to legitimate locations to evade defenses and blend into victim environments.CitationCrowdstrike HuntReport 2022 |
| Enterprise | T1588.001 | MalwareSub-technique | Aquatic Panda has acquired and used njRAT in its operations.[1] |
| Enterprise | T1518.001 | Security Software DiscoverySub-technique | Aquatic Panda has attempted to discover third party endpoint detection and response (EDR) tools on compromised systems.[1] |
| Enterprise | T1059.003 | Windows Command ShellSub-technique | Aquatic Panda has attempted and failed to run Bash commands on a Windows host by passing them to |
| Enterprise | T1685 | Disable or Modify Tools | Aquatic Panda has attempted to stop endpoint detection and response (EDR) tools on compromised systems.[1] |
| Enterprise | T1033 | System Owner/User Discovery | Aquatic Panda gathers information on recently logged-in users on victim devices.CitationCrowdstrike HuntReport 2022 |
| Enterprise | T1047 | Windows Management Instrumentation | Aquatic Panda used WMI for lateral movement in victim environments.CitationCrowdstrike HuntReport 2022 |
| Enterprise | T1588.002 | ToolSub-technique | Aquatic Panda has acquired and used Cobalt Strike in its operations.[1] |
| Enterprise | T1595.002 | Vulnerability ScanningSub-technique | Aquatic Panda has used publicly accessible DNS logging services to identify servers vulnerable to Log4j (CVE 2021-44228).[1] |
| Enterprise | T1003.001 | LSASS MemorySub-technique | Aquatic Panda has attempted to harvest credentials through LSASS memory dumping.[1] |
| Enterprise | T1021 | Remote Services | Aquatic Panda used remote scheduled tasks to install malicious software on victim systems during lateral movement actions.CitationCrowdstrike HuntReport 2022 |
| Enterprise | T1082 | System Information Discovery | Aquatic Panda has used native OS commands to understand privilege levels and system details.[1] |
| Enterprise | T1218.011 | Rundll32Sub-technique | Aquatic Panda used rundll32.exe to proxy execution of a malicious DLL file identified as a keylogging binary.CitationCrowdstrike HuntReport 2022 |
| Enterprise | T1685.005 | Clear Windows Event LogsSub-technique | Aquatic Panda clears Windows Event Logs following activity to evade defenses.CitationCrowdstrike HuntReport 2022 |
| Enterprise | T1078.002 | Domain AccountsSub-technique | Aquatic Panda used multiple mechanisms to capture valid user accounts for victim domains to enable lateral movement and access to additional hosts in victim environments.CitationCrowdstrike HuntReport 2022 |
| Enterprise | T1560.001 | Archive via UtilitySub-technique | Aquatic Panda has used several publicly available tools, including WinRAR and 7zip, to compress collected files and memory dumps prior to exfiltration.[1]CitationCrowdstrike HuntReport 2022 |
| Enterprise | T1059.001 | PowerShellSub-technique | Aquatic Panda has downloaded additional scripts and executed Base64 encoded commands in PowerShell.[1] |
Groups, software, and campaigns
S0645: Wevtutil
S0141: Winnti for Windows
Winnti for Windows is a modular remote access Trojan (RAT) that has been used likely by multiple groups to carry out intrusions in various regions since at least 2010, including by one group referred to as the same name, Winnti Group.[1][2][3][4]. The Linux variant is tracked separately under Winnti for Linux.[5]
S0385: njRAT
S0154: Cobalt Strike
Cobalt Strike is a commercial, full-featured, remote access tool that bills itself as “adversary simulation software designed to execute targeted attacks and emulate the post-exploitation actions of advanced threat actors”. Cobalt Strike’s interactive post-exploit capabilities cover the full range of ATT&CK tactics, all executed within a single, integrated system.[1]
In addition to its own capabilities, Cobalt Strike leverages the capabilities of other well-known tools such as Metasploit and Mimikatz.[1]
S0596: ShadowPad
S0430: Winnti for Linux
Winnti for Linux is a trojan, seen since at least 2015, designed specifically for targeting Linux systems. Reporting indicates the winnti malware family is shared across a number of actors including Winnti Group. The Windows variant is tracked separately under Winnti for Windows.[1]
All related ATT&CK context
Object version and sync metadata
The fields below describe the current mirrored snapshot. When Glexia retains multiple ATT&CK source imports, you can open the table to compare the same object across releases (hashes and MITRE timestamps). For MITRE’s own release notes and roadmap, see ATT&CK resources — Updates.
Imported snapshots across ATT&CK releases(2)
| Release | Bundle imported | Object version | Modified | Status | Raw hash |
|---|---|---|---|---|---|
| 19.2 | 2.0 | Current bundle | 87db86640785… | ||
| 19.1 | 2.0 | Older bundle | 43364e36184d… |
Mirrored ATT&CK source object
The raw object is retained through the mirrored ATT&CK source bundle and object hash. The raw endpoint returns the exact object from the mirrored bundle when available.
External references and citations
MITRE external references are preserved separately from Glexia analysis so citations remain traceable to their original source records.
- [1]CrowdStrike AQUATIC PANDA December 2021
Wiley, B. et al. (2021, December 29). OverWatch Exposes AQUATIC PANDA in Possession of Log4Shell Exploit Tools During Hands-on Intrusion Attempt. Retrieved January 18, 2022.
Open source URL - [2]mitre-attackG0143Open source URL
Source: MITRE ATT&CK®. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation. Glexia is not affiliated with or endorsed by MITRE.
