Aquatic Panda

APT / StateG0143
Origin🇨🇳 China
Techniques (MITRE ATT&CK)35
SourceMITRE ATT&CK
Target categories: Gambling companies, Government Institutions, Education, Media and Entertainment, Pro-democracy and human rights political organizations, Telecommunications, Religious organization, Cryptocurrency, Medical, Covid-19 research organizations
Targeted regions: Australia · China · France · Germany · Hong Kong · Japan · Mongolia · Nepal · Nigeria · Philippines +5
Also known as:BRONZE UNIVERSITYBountyGladCHROMIUMCharcoal TyphoonControlXFISHMONGERRed Dev 10Red ScyllaRedHotelTAG-22

Vexday analysis

Aquatic Panda é um grupo APT de origem chinesa com dupla missão de coleta de inteligência e espionagem industrial, ativo pelo menos desde maio de 2020. Suas operações têm como alvos prioritários entidades dos setores de telecomunicações, tecnologia e governo. O grupo é rastreado pelo MITRE ATT&CK sob o identificador G0143, com 35 técnicas documentadas atribuídas ao seu arsenal.

Attack chain

Plausible scenario built from the group's real techniques, ordered by the phases of an attack. Each step shows how the group typically operates.

Arsenal severity46
Impact: High
T1047T1543.003T1003.001T1007T1021EXECExecutionWindows ManagementInstrumentationPERSPersistenceWindows ServiceCREDCredential accessLSASS MemoryDISCDiscoverySystem ServiceDiscoveryLATLateral movementRemote ServicesCOLLCollectionData from LocalSystem

Illustrative chain derived from techniques documented in MITRE ATT&CK — it does not represent a specific past attack. Severity summarizes the known arsenal (kill-chain coverage, actively exploited CVEs, techniques).

Exploited vulnerabilities

No CVEs attributed to this group in public sources (MITRE ATT&CK). Absence of attribution does not mean absence of activity.

Known infrastructure 1597

Real indicators (C2, domains, URLs and hashes) associated with the malware this group uses. Source: abuse.ch (ThreatFox, URLhaus, MalwareBazaar).

ip:port45.221.118.46:80Cobalt Strikethreatfox
ip:port45.221.118.46:443Cobalt Strikethreatfox
ip:port2.56.165.157:991NjRATthreatfox
ip:port38.76.183.197:8082Cobalt Strikethreatfox
ip:port8.222.188.173:443Cobalt Strikethreatfox
ip:port8.219.220.240:7777Cobalt Strikethreatfox
ip:port120.77.42.217:50000Cobalt Strikethreatfox
ip:port209.99.184.234:50050Cobalt Strikethreatfox
ip:port49.235.52.47:80Cobalt Strikethreatfox
ip:port49.235.52.47:3000Cobalt Strikethreatfox
ip:port49.235.52.47:8080Cobalt Strikethreatfox
ip:port49.235.52.47:8083Cobalt Strikethreatfox
ip:port49.235.52.47:443Cobalt Strikethreatfox
ip:port147.139.136.105:8080Cobalt Strikethreatfox
ip:port38.207.177.165:8080Cobalt Strikethreatfox
ip:port147.139.136.105:22Cobalt Strikethreatfox
ip:port147.139.136.105:80Cobalt Strikethreatfox
ip:port147.139.136.105:443Cobalt Strikethreatfox
ip:port2.57.241.129:80Cobalt Strikethreatfox
ip:port38.207.177.165:80Cobalt Strikethreatfox
ip:port38.207.177.165:443Cobalt Strikethreatfox
ip:port45.221.118.46:8080Cobalt Strikethreatfox
ip:port147.139.245.149:801Cobalt Strikethreatfox
ip:port118.24.42.214:443Cobalt Strikethreatfox
ip:port119.45.198.250:55555Cobalt Strikethreatfox
ip:port172.232.97.189:4444Cobalt Strikethreatfox
ip:port47.254.68.68:50050Cobalt Strikethreatfox
ip:port47.251.29.219:50050Cobalt Strikethreatfox
ip:port149.88.66.234:21Cobalt Strikethreatfox
ip:port47.108.86.120:22Cobalt Strikethreatfox

+1597 indicators in total. See them all on the IOCs page.

Aquatic Panda uses real techniques and exploits real flaws. TrueHacking's AI Autonomous Pentest simulates these attacks against your infrastructure and brings more security to your application.

Explore the AI Autonomous Pentest →