Deep Panda — APT Profile
Deep Panda is a suspected Chinese threat group known to target many industries, including government, defense, financial, and telecommunications. The intrusion into healthcare company Anthem has been attributed to Deep Panda. This group is also known as Shell Crew, WebMasters, KungFu Kittens, and PinkPanther. Deep Panda also appears to be known as Black Vine based on the attribution of both group names to the Anthem intrusion. Some analysts track Deep Panda and APT19 as the same group, but it is unclear from open source information if the groups are the same.Also tracked as
Shell Crew, WebMasters, KungFu Kittens, PinkPanther, Black Vine
Tools & malware
- Derusbi Backdoor
- Mivast Backdoor
- Net Network Reconnaissance
- Ping Network Reconnaissance
- Sakula Backdoor
- StreamEx Backdoor
- Tasklist Discovery
Vendor research
- Deep in Thought: Chinese Targeting of National Security Think Tanks Alperovitch
- The Black Vine cyberespionage group Symantec
- RSA Incident Response Emerging Threat Profile: Shell Crew RSA
- ICIT Brief - China’s Espionage Dynasty: Economic Death by a Thousand Cuts ICIT
- The Anthem Hack: All Roads Lead to China ThreatConnect