Aquatic Panda

APT / StateG0143 ↗
Origin🇨🇳 China
Techniques (MITRE ATT&CK)35
SourceMITRE ATT&CK
Target categories: Gambling companies, Government Institutions, Education, Media and Entertainment, Pro-democracy and human rights political organizations, Telecommunications, Religious organization, Cryptocurrency, Medical, Covid-19 research organizations
Targeted regions: Australia · China · France · Germany · Hong Kong · Japan · Mongolia · Nepal · Nigeria · Philippines +5
Also known as:BRONZE UNIVERSITYBountyGladCHROMIUMCharcoal TyphoonControlXFISHMONGERRed Dev 10Red ScyllaRedHotelTAG-22

About the group

Aquatic Panda is a suspected China-based threat group with a dual mission of intelligence collection and industrial espionage. Active since at least May 2020, Aquatic Panda has primarily targeted entities in the telecommunications, technology, and government sectors.

Attack chain

Plausible scenario built from the group's real techniques, ordered by the phases of an attack. Each step shows how the group typically operates.

Arsenal severity46
Impact: High
T1047T1543.003T1003.001T1007T1021EXECExecutionWindows ManagementInstrumentationPERSPersistenceWindows ServiceCREDCredential accessLSASS MemoryDISCDiscoverySystem ServiceDiscoveryLATLateral movementRemote ServicesCOLLCollectionData from LocalSystem

Illustrative chain derived from techniques documented in MITRE ATT&CK — it does not represent a specific past attack. Severity summarizes the known arsenal (kill-chain coverage, actively exploited CVEs, techniques).

Exploited vulnerabilities

No CVEs attributed to this group in public sources (MITRE ATT&CK). Absence of attribution does not mean absence of activity.

Known infrastructure 3144

Real indicators (C2, domains, URLs and hashes) associated with the malware this group uses. Source: abuse.ch (ThreatFox, URLhaus, MalwareBazaar).

ip:port114.215.184.158:8000Cobalt Strikethreatfox
urlhttp://69.49.229.88:443/MQEwCobalt Strikethreatfox
ip:port154.12.17.20:8080Cobalt Strikethreatfox
ip:port154.12.17.20:22Cobalt Strikethreatfox
ip:port154.12.17.20:443Cobalt Strikethreatfox
ip:port154.12.17.20:80Cobalt Strikethreatfox
ip:port129.204.55.230:443Cobalt Strikethreatfox
ip:port47.94.56.71:8080Cobalt Strikethreatfox
ip:port47.94.56.71:80Cobalt Strikethreatfox
ip:port47.94.56.71:443Cobalt Strikethreatfox
md5_hash1cf8cce965f8f2089ce67ef811b29d13NjRATthreatfox
sha256_hashd7fea5f6217db6e04f75333a65a46cdfcc523c7f3ddc29cfaecb18cd8876ea98NjRATthreatfox
sha1_hashca868ac1e4f42282fb74865fc2f9edf38b052e4bNjRATthreatfox
sha256_hashd5c4983535d57d69fc6f8c09ff4a3838d6a61ac6b149de67b89c0c062968d9cdNjRATthreatfox
sha1_hash19dc42491a499830d7638933b5f457740ffce395NjRATthreatfox
md5_hash1742ad51f743c9e518abec7fc6f9451bNjRATthreatfox
ip:port45.227.253.132:8080Cobalt Strikethreatfox
ip:port45.227.253.132:443Cobalt Strikethreatfox
ip:port45.227.253.132:80Cobalt Strikethreatfox
ip:port45.227.253.132:32775Cobalt Strikethreatfox
ip:port117.158.148.164:65535Cobalt Strikethreatfox
ip:port38.76.190.209:8888Cobalt Strikethreatfox
ip:port188.227.14.105:8080Cobalt Strikethreatfox
ip:port186.241.115.168:12443Cobalt Strikethreatfox
ip:port109.206.247.245:10881Cobalt Strikethreatfox
ip:port43.134.112.45:7500Cobalt Strikethreatfox
ip:port43.134.112.45:8080Cobalt Strikethreatfox
ip:port43.134.112.45:7000Cobalt Strikethreatfox
ip:port43.134.112.45:80Cobalt Strikethreatfox
ip:port43.134.112.45:443Cobalt Strikethreatfox

+3144 indicators in total. See them all on the IOCs page.

Aquatic Panda uses real techniques and exploits real flaws. TrueHacking's AI Autonomous Pentest simulates these attacks against your infrastructure and brings more security to your application.

Explore the AI Autonomous Pentest →