Deep Panda
Deep Panda is a suspected Chinese-based threat group that has targeted several industries, including government, defense, financial, and telecommunications. Deep Panda is attributed with the intrusion into the healthcare company Anthem. Deep Panda is also linked to Black Vine based on both group names being attributed to the Anthem intrusion. Some researchers have linked Deep Panda and APT19 as being the same group, but it is unclear from open source information if the groups are the same.
Other names for this threat
APT26, Black Vine, Group 13, JerseyMikes, KungFu Kittens, PinkPanther, Shell Crew, Turbine Panda, WebMasters
This is a collection of rules based on the presence of indicators of compromise publicly reported as associated with this malicious actor.
Suspicious DNS Request - Deep Panda Related Domain Observed
Description
This detection identifies a request to resolve a domain publicly reported as associated with this malicious actor. Malicious actors may use compromised websites for malicious purposes.
Recommendation
This alert may have been caused by normal web browsing activity by the end user. Review the alert in question. If necessary, rebuild the host from a known, good source and have the user change their password.
MITRE ATT&CK Techniques
- Acquire Infrastructure - T1583
- Domains - T1583.001
- Compromise Infrastructure - T1584
- Domains - T1584.001
Suspicious Process - Deep Panda Related Binary Executed
Description
This detection identifies the execution of a file with a hash publicly reported as associated with this malicious actor. Malicious actors may use common System Administration tools for malicious purposes.
Recommendation
Review the alert in question. If necessary, rebuild the host from a known, good source and have the user change their password.
Suspicious Web Request - Deep Panda Related Domain Observed
Description
This detection identifies a request to a domain publicly reported as associated with this malicious actor. Malicious actors may compromise websites for malicious purposes.
Recommendation
This alert may have been caused by normal web browsing activity by the end user. Review the alert in question. If necessary, rebuild the host from a known, good source and have the user change their password.
MITRE ATT&CK Techniques
- Acquire Infrastructure - T1583
- Domains - T1583.001
- Virtual Private Server - T1583.003
- Server - T1583.004
- Compromise Infrastructure - T1584
- Domains - T1584.001
- Virtual Private Server - T1584.003
- Server - T1584.004