Deep Panda
MITREUnknown
Unknown
Unknown
[Deep Panda](https://attack.mitre.org/groups/G0009) is a suspected Chinese threat group known to target many industries, including government, defense, financial, and telecommunications. (Citation: Alperovitch 2014) The intrusion into healthcare company Anthem has been attributed to [Deep Panda](https://attack.mitre.org/groups/G0009). (Citation: ThreatConnect Anthem) This group is also known as Shell Crew, WebMasters, KungFu Kittens, and PinkPanther. (Citation: RSA Shell Crew) [Deep Panda](https://attack.mitre.org/groups/G0009) also appears to be known as Black Vine based on the attribution of both group names to the Anthem intrusion. (Citation: Symantec Black Vine) Some analysts track [Deep Panda](https://attack.mitre.org/groups/G0009) and [APT19](https://attack.mitre.org/groups/G0073) as the same group, but it is unclear from open source information if the groups are the same. (Citation: ICIT China's Espionage Jul 2016)
Tecniche Utilizzate (10)
| ID | ATT&CK | Tattiche |
|---|---|---|
| T1018 | Remote System Discovery | - |
| T1021.002 | SMB/Windows Admin Shares | - |
| T1027.005 | Indicator Removal from Tools | - |
| T1047 | Windows Management Instrumentation | - |
| T1057 | Process Discovery | - |
| T1059.001 | PowerShell | - |
| T1218.010 | Regsvr32 | - |
| T1505.003 | Web Shell | - |
| T1546.008 | Accessibility Features | - |
| T1564.003 | Hidden Window | - |
Alias (525)
Malware Utilizzato (7)
Metadata
| ID: | 929 |
| Created: | 13/01/2026 17:48 |
| Updated: | 06/03/2026 16:00 |