Deep Panda

APT / StateG0009 ↗
Origin🇨🇳 China
Techniques (MITRE ATT&CK)10
SourceMITRE ATT&CK
State sponsor: ChinaAttribution confidence: 50%Target categories: Private sector, Military
Targeted regions: United States
Also known as:BRONZE FIRESTONEBlack VineCheckered TyphoonCodosoG0009G0073Group 13KungFu KittensPinkPantherPupaShell CrewSunshop GroupTEMP.AvengersWebMasters

About the group

Deep Panda is a suspected Chinese threat group known to target many industries, including government, defense, financial, and telecommunications. The intrusion into healthcare company Anthem has been attributed to Deep Panda. This group is also known as Shell Crew, WebMasters, KungFu Kittens, and PinkPanther. Deep Panda also appears to be known as Black Vine based on the attribution of both group names to the Anthem intrusion. Some analysts track Deep Panda and APT19 as the same group, but it is unclear from open source information if the groups are the same.

Attack chain

Plausible scenario built from the group's real techniques, ordered by the phases of an attack. Each step shows how the group typically operates.

Arsenal severity21
Impact: High
T1047T1505.003T1546.008T1018EXECExecutionWindows ManagementInstrumentationPERSPersistenceWeb ShellPRIVPrivilege escalationAccessibilityFeaturesDISCDiscoveryRemote SystemDiscoveryLATLateral movementSMB/Windows AdminShares

Illustrative chain derived from techniques documented in MITRE ATT&CK — it does not represent a specific past attack. Severity summarizes the known arsenal (kill-chain coverage, actively exploited CVEs, techniques).

Techniques (MITRE ATT&CK) 10

How the group operates, mapped to the MITRE ATT&CK matrix and organized by the phases of an attack.

Exploited vulnerabilities

No CVEs attributed to this group in public sources (MITRE ATT&CK). Absence of attribution does not mean absence of activity.

Deep Panda uses real techniques and exploits real flaws. TrueHacking's AI Autonomous Pentest simulates these attacks against your infrastructure and brings more security to your application.

Explore the AI Autonomous Pentest →