Deep Panda — APT Profile
Deep Panda is a suspected Chinese threat group known to target many industries, including government, defense, financial, and telecommunications. The intrusion into healthcare company Anthem has been attributed to Deep Panda. This group is also known as Shell Crew, WebMasters, KungFu Kittens, and PinkPanther. Deep Panda also appears to be known as Black Vine based on the attribution of both group names to the Anthem intrusion. Some analysts track Deep Panda and APT19 as the same group, but it is unclear from open source information if the groups are the same.Description reproduced from MITRE ATT&CK. © The MITRE Corporation, reproduced and distributed with permission.
Also tracked as
Shell Crew, WebMasters, KungFu Kittens, PinkPanther, Black Vine
IntelFusions coverage (2)
- Spies and ransomware crews root Cisco firewall servers 2026-09-09 · Vulnerabilities
- Deep Panda Exploits Log4Shell in VMware Horizon to Deploy Milestone Backdoor and Novel Kernel Rootkit 2026-02-16 · Nation-State
Tools & malware
- Derusbi Backdoor
- Mivast Backdoor
- Net Network Reconnaissance
- Ping Network Reconnaissance
- Sakula Backdoor
- StreamEx Backdoor
- Tasklist Discovery
Vendor research
- The Anthem Hack: All Roads Lead to China ThreatConnect Research Team
- Deep in Thought: Chinese Targeting of National Security Think Tanks Alperovitch
- The Black Vine cyberespionage group Symantec
- RSA Incident Response Emerging Threat Profile: Shell Crew RSA
- ICIT Brief - China’s Espionage Dynasty: Economic Death by a Thousand Cuts ICIT
- The Anthem Hack: All Roads Lead to China ThreatConnect