Deep Panda

APT / StateG0009
Origin🇨🇳 China
Techniques (MITRE ATT&CK)10
SourceMITRE ATT&CK
State sponsor: ChinaAttribution confidence: 50%Target categories: Private sector, Military
Targeted regions: United States
Also known as:BRONZE FIRESTONEBlack VineCheckered TyphoonCodosoG0009G0073Group 13KungFu KittensPinkPantherPupaShell CrewSunshop GroupTEMP.AvengersWebMasters

Vexday analysis

Deep Panda (também identificado como Shell Crew, WebMasters, KungFu Kittens, PinkPanther e Black Vine) é um grupo APT de origem chinesa suspeita, catalogado pelo MITRE ATT&CK como G0009, com 10 técnicas documentadas. O grupo é conhecido por atacar múltiplos setores, incluindo governo, defesa, finanças e telecomunicações, com a intrusão à empresa de saúde Anthem sendo atribuída a ele. A nomenclatura Black Vine também está vinculada a esse mesmo ator com base na atribuição compartilhada ao incidente Anthem. Alguns analistas apontam similaridades entre Deep Panda e APT19, porém as informações públicas disponíveis não são suficientes para confirmar se se trata do mesmo grupo.

Attack chain

Plausible scenario built from the group's real techniques, ordered by the phases of an attack. Each step shows how the group typically operates.

Arsenal severity21
Impact: High
T1047T1505.003T1546.008T1018EXECExecutionWindows ManagementInstrumentationPERSPersistenceWeb ShellPRIVPrivilege escalationAccessibilityFeaturesDISCDiscoveryRemote SystemDiscoveryLATLateral movementSMB/Windows AdminShares

Illustrative chain derived from techniques documented in MITRE ATT&CK — it does not represent a specific past attack. Severity summarizes the known arsenal (kill-chain coverage, actively exploited CVEs, techniques).

Techniques (MITRE ATT&CK) 10

How the group operates, mapped to the MITRE ATT&CK matrix and organized by the phases of an attack.

Exploited vulnerabilities

No CVEs attributed to this group in public sources (MITRE ATT&CK). Absence of attribution does not mean absence of activity.

Deep Panda uses real techniques and exploits real flaws. TrueHacking's AI Autonomous Pentest simulates these attacks against your infrastructure and brings more security to your application.

Explore the AI Autonomous Pentest →