Deep Panda
Also reported as Shell Crew, WebMasters, KungFu Kittens, PinkPanther and Black Vine.
Reports per quarter
Techniques seen in the last two years
- T1053.005 8 reports reports only
- T1057 6 reports in ATT&CK
- T1082 6 reports reports only
- T1105 6 reports reports only
- T1059.001 5 reports in ATT&CK
- T1059.003 5 reports reports only
- T1071.001 5 reports reports only
- T1204.002 5 reports reports only
- T1566.001 5 reports reports only
- T1005 4 reports reports only
Show all 269 techniques Show fewer
- T1027 4 reports reports only
- T1033 4 reports reports only
- T1041 4 reports reports only
- T1140 4 reports reports only
- T1189 4 reports reports only
- T1482 4 reports reports only
- T1572 4 reports reports only
- T1007 3 reports reports only
- T1016 3 reports reports only
- T1018 3 reports in ATT&CK
- T1046 3 reports reports only
- T1047 3 reports in ATT&CK
- T1055.002 3 reports reports only
- T1059 3 reports reports only
- T1059.005 3 reports reports only
- T1068 3 reports reports only
- T1069.002 3 reports reports only
- T1070.004 3 reports reports only
- T1083 3 reports reports only
- T1087.001 3 reports reports only
- T1087.002 3 reports reports only
- T1132.001 3 reports reports only
- T1136.001 3 reports reports only
- T1190 3 reports reports only
- T1219 3 reports reports only
- T1505.003 3 reports in ATT&CK
- T1518.001 3 reports reports only
- T1566 3 reports reports only
- T1570 3 reports reports only
- T1574.001 3 reports reports only
- T1003.001 2 reports reports only
- T1003.002 2 reports reports only
- T1008 2 reports reports only
- T1021.001 2 reports reports only
- T1021.002 2 reports in ATT&CK
- T1027.009 2 reports reports only
- T1036 2 reports reports only
- T1036.005 2 reports reports only
- T1049 2 reports reports only
- T1055 2 reports reports only
- T1055.004 2 reports reports only
- T1056.001 2 reports reports only
- T1059.006 2 reports reports only
- T1059.007 2 reports reports only
- T1069.001 2 reports reports only
- T1071 2 reports reports only
- T1071.004 2 reports reports only
- T1078 2 reports reports only
- T1090 2 reports reports only
- T1090.001 2 reports reports only
- T1095 2 reports reports only
- T1098 2 reports reports only
- T1098.007 2 reports reports only
- T1104 2 reports reports only
- T1119 2 reports reports only
- T1124 2 reports reports only
- T1129 2 reports reports only
- T1133 2 reports reports only
- T1135 2 reports reports only
- T1136 2 reports reports only
- T1204 2 reports reports only
- T1217 2 reports reports only
- T1496 2 reports reports only
- T1505.004 2 reports reports only
- T1543.003 2 reports reports only
- T1547.001 2 reports reports only
- T1548 2 reports reports only
- T1555.003 2 reports reports only
- T1560 2 reports reports only
- T1560.001 2 reports reports only
- T1566.002 2 reports reports only
- T1566.004 2 reports reports only
- T1567 2 reports reports only
- T1571 2 reports reports only
- T1573.001 2 reports reports only
- T1583 2 reports reports only
- T1583.003 2 reports reports only
- T1587.001 2 reports reports only
- T1590 2 reports reports only
- T1595 2 reports reports only
- T1595.002 2 reports reports only
- T1608 2 reports reports only
- T1608.001 2 reports reports only
- T1608.002 2 reports reports only
- T1608.006 2 reports reports only
- T1620 2 reports reports only
- T1649 2 reports reports only
- T1003 1 report reports only
- T1010 1 report reports only
- T1012 1 report reports only
- T1016.001 1 report reports only
- T1020 1 report reports only
- T1021 1 report reports only
- T1021.004 1 report reports only
- T1021.005 1 report reports only
- T1021.006 1 report reports only
- T1036.003 1 report reports only
- T1037 1 report reports only
- T1037.001 1 report reports only
- T1039 1 report reports only
- T1040 1 report reports only
- T1048 1 report reports only
- T1053 1 report reports only
- T1053.003 1 report reports only
- T1055.001 1 report reports only
- T1055.003 1 report reports only
- T1055.009 1 report reports only
- T1055.012 1 report reports only
- T1056 1 report reports only
- T1059.002 1 report reports only
- T1059.004 1 report reports only
- T1059.009 1 report reports only
- T1059.010 1 report reports only
- T1059.011 1 report reports only
- T1069 1 report reports only
- T1069.003 1 report reports only
- T1070 1 report reports only
- T1072 1 report reports only
- T1074 1 report reports only
- T1074.001 1 report reports only
- T1074.002 1 report reports only
- T1078.002 1 report reports only
- T1078.003 1 report reports only
- T1078.004 1 report reports only
- T1087 1 report reports only
- T1087.004 1 report reports only
- T1090.003 1 report reports only
- T1091 1 report reports only
- T1098.001 1 report reports only
- T1098.003 1 report reports only
- T1098.004 1 report reports only
- T1098.005 1 report reports only
- T1098.006 1 report reports only
- T1102 1 report reports only
- T1102.002 1 report reports only
- T1113 1 report reports only
- T1114 1 report reports only
- T1114.001 1 report reports only
- T1114.002 1 report reports only
- T1114.003 1 report reports only
- T1115 1 report reports only
- T1120 1 report reports only
- T1123 1 report reports only
- T1125 1 report reports only
- T1132 1 report reports only
- T1134 1 report reports only
- T1134.001 1 report reports only
- T1136.002 1 report reports only
- T1137 1 report reports only
- T1137.006 1 report reports only
- T1195 1 report reports only
- T1195.001 1 report reports only
- T1195.002 1 report reports only
- T1199 1 report reports only
- T1200 1 report reports only
- T1201 1 report reports only
- T1203 1 report reports only
- T1204.001 1 report reports only
- T1204.004 1 report reports only
- T1210 1 report reports only
- T1213 1 report reports only
- T1213.001 1 report reports only
- T1213.002 1 report reports only
- T1213.003 1 report reports only
- T1218.007 1 report reports only
- T1484 1 report reports only
- T1484.001 1 report reports only
- T1485 1 report reports only
- T1486 1 report reports only
- T1489 1 report reports only
- T1490 1 report reports only
- T1491.002 1 report reports only
- T1497 1 report reports only
- T1497.001 1 report reports only
- T1497.003 1 report reports only
- T1498 1 report reports only
- T1505 1 report reports only
- T1518 1 report reports only
- T1528 1 report reports only
- T1529 1 report reports only
- T1530 1 report reports only
- T1534 1 report reports only
- T1537 1 report reports only
- T1538 1 report reports only
- T1543 1 report reports only
- T1543.002 1 report reports only
- T1543.004 1 report reports only
- T1546 1 report reports only
- T1546.003 1 report reports only
- T1546.004 1 report reports only
- T1546.008 1 report in ATT&CK
- T1546.012 1 report reports only
- T1546.015 1 report reports only
- T1547 1 report reports only
- T1547.002 1 report reports only
- T1547.005 1 report reports only
- T1547.009 1 report reports only
- T1548.002 1 report reports only
- T1550 1 report reports only
- T1550.001 1 report reports only
- T1550.002 1 report reports only
- T1552 1 report reports only
- T1554 1 report reports only
- T1555 1 report reports only
- T1556 1 report reports only
- T1556.006 1 report reports only
- T1556.009 1 report reports only
- T1558.003 1 report reports only
- T1559 1 report reports only
- T1560.002 1 report reports only
- T1564.004 1 report reports only
- T1565 1 report reports only
- T1565.001 1 report reports only
- T1566.003 1 report reports only
- T1567.001 1 report reports only
- T1567.002 1 report reports only
- T1569 1 report reports only
- T1569.002 1 report reports only
- T1573 1 report reports only
- T1573.002 1 report reports only
- T1574 1 report reports only
- T1574.011 1 report reports only
- T1578 1 report reports only
- T1580 1 report reports only
- T1583.001 1 report reports only
- T1583.004 1 report reports only
- T1583.006 1 report reports only
- T1584 1 report reports only
- T1584.004 1 report reports only
- T1585 1 report reports only
- T1585.002 1 report reports only
- T1586.002 1 report reports only
- T1587 1 report reports only
- T1587.003 1 report reports only
- T1588 1 report reports only
- T1588.002 1 report reports only
- T1588.003 1 report reports only
- T1588.004 1 report reports only
- T1588.007 1 report reports only
- T1589.002 1 report reports only
- T1590.005 1 report reports only
- T1592 1 report reports only
- T1595.001 1 report reports only
- T1598 1 report reports only
- T1602 1 report reports only
- T1602.001 1 report reports only
- T1602.002 1 report reports only
- T1608.003 1 report reports only
- T1608.004 1 report reports only
- T1608.005 1 report reports only
- T1613 1 report reports only
- T1614 1 report reports only
- T1614.001 1 report reports only
- T1615 1 report reports only
- T1619 1 report reports only
- T1622 1 report reports only
- T1652 1 report reports only
- T1654 1 report reports only
- T1657 1 report reports only
Counts come from technique IDs in the actor's report text. “Reports only” means reports name the technique but MITRE ATT&CK® does not list it for this actor.
Also listed by ATT&CK
CVEs named in reports
- CVE-2008-3431 KEV
- CVE-2010-0232 KEV
- CVE-2010-2861 KEV ransomware
- CVE-2010-4398 KEV
- CVE-2011-3402 KEV
- CVE-2012-0151 KEV
- CVE-2012-0158 KEV ransomware
- CVE-2012-4792 KEV
- CVE-2012-4969 KEV
- CVE-2013-3900 KEV
- CVE-2014-0160 KEV
- CVE-2014-0322 KEV
Show all 203 CVEs Show fewer
- CVE-2014-0502 KEV
- CVE-2014-1761 KEV
- CVE-2014-1776 KEV
- CVE-2014-1812 KEV ransomware
- CVE-2014-4113 KEV
- CVE-2014-6271 KEV
- CVE-2014-6277
- CVE-2014-6278 KEV
- CVE-2014-6332 KEV
- CVE-2014-7169 KEV
- CVE-2014-7186
- CVE-2014-7187
- CVE-2015-2360 KEV
- CVE-2015-5119 KEV
- CVE-2015-5122 KEV
- CVE-2015-6585
- CVE-2016-0167 KEV ransomware
- CVE-2017-0199 KEV ransomware
- CVE-2017-10271 KEV ransomware
- CVE-2017-1099
- CVE-2017-11774 KEV
- CVE-2017-1182
- CVE-2017-11882 KEV ransomware
- CVE-2017-12149 KEV ransomware
- CVE-2017-12824
- CVE-2017-15399
- CVE-2017-15944 KEV
- CVE-2017-5638 KEV ransomware
- CVE-2017-6327 KEV
- CVE-2017-6328
- CVE-2017-8291 KEV
- CVE-2017-8570 KEV
- CVE-2017-8759 KEV
- CVE-2017-9805 KEV
- CVE-2018-0802 KEV ransomware
- CVE-2018-0824 KEV
- CVE-2018-1207
- CVE-2018-13379 KEV ransomware
- CVE-2018-15961 KEV
- CVE-2018-15982 KEV ransomware
- CVE-2018-4878 KEV ransomware
- CVE-2018-7600 KEV ransomware
- CVE-2018-7602 KEV ransomware
- CVE-2018-8174 KEV ransomware
- CVE-2018-8581 KEV ransomware
- CVE-2018-8611 KEV
- CVE-2018-8639 KEV ransomware
- CVE-2019-0604 KEV ransomware
- CVE-2019-0708 KEV ransomware
- CVE-2019-0803 KEV ransomware
- CVE-2019-10149 KEV
- CVE-2019-11510 KEV ransomware
- CVE-2019-11580 KEV ransomware
- CVE-2019-1458 KEV ransomware
- CVE-2019-16098
- CVE-2019-1652 KEV
- CVE-2019-1653 KEV
- CVE-2019-16920 KEV
- CVE-2019-18935 KEV ransomware
- CVE-2019-19781 KEV ransomware
- CVE-2019-3396 KEV ransomware
- CVE-2019-3398 KEV
- CVE-2019-8394 KEV
- CVE-2019-9621 KEV
- CVE-2020-0601 KEV
- CVE-2020-0674 KEV
- CVE-2020-0688 KEV ransomware
- CVE-2020-0787 KEV ransomware
- CVE-2020-0796 KEV ransomware
- CVE-2020-0986 KEV
- CVE-2020-10189 KEV
- CVE-2020-10198
- CVE-2020-1040 KEV
- CVE-2020-116511
- CVE-2020-11652 KEV
- CVE-2020-11899 KEV
- CVE-2020-1350 KEV
- CVE-2020-1380 KEV
- CVE-2020-1472 KEV ransomware
- CVE-2020-14750 KEV
- CVE-2020-14882 KEV
- CVE-2020-1599
- CVE-2020-2021 KEV ransomware
- CVE-2020-3125
- CVE-2020-3529
- CVE-2020-5902 KEV ransomware
- CVE-2020-6789
- CVE-2020-7961 KEV
- CVE-2020-8243 KEV
- CVE-2020-8260 KEV
- CVE-2020-8515 KEV
- CVE-2021-1636
- CVE-2021-1675 KEV ransomware
- CVE-2021-1732 KEV ransomware
- CVE-2021-1844
- CVE-2021-1879 KEV
- CVE-2021-20016 KEV ransomware
- CVE-2021-21166 KEV
- CVE-2021-22894 KEV
- CVE-2021-22899 KEV
- CVE-2021-22900 KEV
- CVE-2021-22941 KEV ransomware
- CVE-2021-26084 KEV ransomware
- CVE-2021-26411 KEV ransomware
- CVE-2021-26855 KEV ransomware
- CVE-2021-26857 KEV ransomware
- CVE-2021-26858 KEV ransomware
- CVE-2021-27065 KEV ransomware
- CVE-2021-30116 KEV ransomware
- CVE-2021-30551 KEV
- CVE-2021-31195
- CVE-2021-31196 KEV
- CVE-2021-31206
- CVE-2021-31207 KEV ransomware
- CVE-2021-3156 KEV
- CVE-2021-33742 KEV
- CVE-2021-34473 KEV ransomware
- CVE-2021-34523 KEV ransomware
- CVE-2021-34527 KEV ransomware
- CVE-2021-35211 KEV ransomware
- CVE-2021-36798
- CVE-2021-36934 KEV
- CVE-2021-36942 KEV ransomware
- CVE-2021-40444 KEV ransomware
- CVE-2021-40449 KEV ransomware
- CVE-2021-40539 KEV ransomware
- CVE-2021-4104
- CVE-2021-41379 KEV ransomware
- CVE-2021-44077 KEV
- CVE-2021-44207 KEV
- CVE-2021-44228 KEV ransomware
- CVE-2021-44515 KEV
- CVE-2021-44832
- CVE-2021-45046 KEV ransomware
- CVE-2021-45105
- CVE-2022-21587 KEV ransomware
- CVE-2022-21882 KEV ransomware
- CVE-2022-22954 KEV ransomware
- CVE-2022-22957
- CVE-2022-22958
- CVE-2022-24500
- CVE-2022-24521 KEV ransomware
- CVE-2022-24682 KEV ransomware
- CVE-2022-24934
- CVE-2022-26134 KEV ransomware
- CVE-2022-26809
- CVE-2022-26923 KEV
- CVE-2022-27924 KEV ransomware
- CVE-2022-27925 KEV ransomware
- CVE-2022-30190 KEV ransomware
- CVE-2022-30333 KEV ransomware
- CVE-2022-31199 KEV ransomware
- CVE-2022-37042 KEV ransomware
- CVE-2022-41080 KEV ransomware
- CVE-2022-41082 KEV ransomware
- CVE-2022-47966 KEV ransomware
- CVE-2022-47986 KEV ransomware
- CVE-2023-0669 KEV ransomware
- CVE-2023-21746
- CVE-2023-23397 KEV
- CVE-2023-27350 KEV ransomware
- CVE-2023-27532 KEV ransomware
- CVE-2023-27997 KEV ransomware
- CVE-2023-28461 KEV ransomware
- CVE-2023-32315 KEV
- CVE-2023-3466
- CVE-2023-3467
- CVE-2023-3519 KEV ransomware
- CVE-2023-36033 KEV
- CVE-2023-38831 KEV ransomware
- CVE-2023-45727 KEV
- CVE-2023-46805 KEV ransomware
- CVE-2023-48788 KEV ransomware
- CVE-2024-0012 KEV ransomware
- CVE-2024-21887 KEV ransomware
- CVE-2024-21893 KEV ransomware
- CVE-2024-21983
- CVE-2024-24919 KEV ransomware
- CVE-2024-27956
- CVE-2024-30051 KEV ransomware
- CVE-2024-3400 KEV ransomware
- CVE-2024-36401 KEV
- CVE-2024-42009 KEV
- CVE-2024-4577 KEV ransomware
- CVE-2024-47575 KEV
- CVE-2024-6473
- CVE-2024-9474 KEV ransomware
- CVE-2025-2783 KEV
- CVE-2025-31324 KEV ransomware
- CVE-2025-55182 KEV ransomware
- CVE-2026-21236
KEV marks a CVE in CISA's Known Exploited Vulnerabilities Catalog, and “ransomware” marks one that the catalog records as used in ransomware campaigns.
Reports
-
Deep in Thought: Chinese Targeting of National Security Think Tanks »
The title opens Wayback Machine, not the publisher’s page. Archived copy on ORKL Detailsfor Deep in Thought: Chinese Targeting of National Security Think Tanks »
-
Emissary Panda, APT 27, LuckyMouse, Bronze Union
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Emissary Panda, APT 27, LuckyMouse, Bronze Union
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor APT 19, Deep Panda, C0d0so0
-
Turbine Panda, APT 26, Shell Crew, WebMasters, KungFu Kittens
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Turbine Panda, APT 26, Shell Crew, WebMasters, KungFu Kittens
Show all 650 reports Show fewer
-
Malware-Free Intrusions: Adversary Tricks and CrowdStrike Treats »
The title opens Wayback Machine, not the publisher’s page. Archived copy on ORKL Detailsfor Malware-Free Intrusions: Adversary Tricks and CrowdStrike Treats »
-
ICIT Brief – China’s Espionage Dynasty: Economic Death by a Thousand Cuts
The title opens Wayback Machine, not the publisher’s page. Archived copy on ORKL Detailsfor ICIT Brief – China’s Espionage Dynasty: Economic Death by a Thousand Cuts
-
Emissary Panda, APT 27, LuckyMouse, Bronze Union
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Emissary Panda, APT 27, LuckyMouse, Bronze Union
-
Team46 and TaxOff: two sides of the same coin
The original link failed its last check. Original publisher Detailsfor Team46 and TaxOff: two sides of the same coin
-
Security Response - Black Vine Cyberespionage Group.pdf
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Security Response - Black Vine Cyberespionage Group.pdf
-
Eu_Repo_C_APT_profile_Conti_Wizard_Spider_dc2a733e18.pdf
The original link failed its last check. Original publisher Detailsfor Eu_Repo_C_APT_profile_Conti_Wizard_Spider_dc2a733e18.pdf
-
The original link failed its last check. Original publisher Detailsfor RedSense
-
The original link failed its last check. Original publisher Detailsfor RedSense
-
Russian Ransomware C2 Network Discovered in Censys Data
The original link failed its last check. Original publisher Detailsfor Russian Ransomware C2 Network Discovered in Censys Data
-
The original link failed its last check. Original publisher Detailsfor RedSense
-
yir-cyber-threats-annex-download.pdf
The original link failed its last check. Original publisher Detailsfor yir-cyber-threats-annex-download.pdf
-
The original link failed its last check. Original publisher Detailsfor RedSense
-
New Milestones for Deep Panda: Log4Shell and Digitally Signed Fire Chili Rootkits
The link to Mirror on Box failed its last check. Mirror on Box Detailsfor New Milestones for Deep Panda: Log4Shell and Digitally Signed Fire Chili Rootkits
-
Chinese Hackers Target VMware Horizon Servers with Log4Shell to Deploy Rootkit
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Chinese Hackers Target VMware Horizon Servers with Log4Shell to Deploy Rootkit
-
New Milestones for Deep Panda- Log4Shell and Digitally Signed Fire Chili Rootkits
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor New Milestones for Deep Panda- Log4Shell and Digitally Signed Fire Chili Rootkits
-
New Milestones for Deep Panda_ Log4Shell and Digitally Signed Fire Chili Rootkits
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor New Milestones for Deep Panda_ Log4Shell and Digitally Signed Fire Chili Rootkits
-
Legitimate Sites used as Cobalt Strike C2s against Indian Government
The original link failed its last check. Original publisher Detailsfor Legitimate Sites used as Cobalt Strike C2s against Indian Government
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor 2021trends.pdf
-
The original link failed its last check. Original publisher Detailsfor RedSense
-
VMware Exposing Malware In Linux Based Multi Cloud Environments
The original link failed its last check. Original publisher Detailsfor VMware Exposing Malware In Linux Based Multi Cloud Environments
-
Winnti is Coming - Evolution after Prosecution@HITCON2021
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Winnti is Coming - Evolution after Prosecution@HITCON2021
-
sneak-peek-ch1-2-finding-beacons-in-the-dark.pdf
The original link failed its last check. Original publisher Detailsfor sneak-peek-ch1-2-finding-beacons-in-the-dark.pdf
-
Masters of Mimicry: new APT group ChamelGang and its arsenal
The original link failed its last check. Original publisher Detailsfor Masters of Mimicry: new APT group ChamelGang and its arsenal
-
Masters of Mimicry: new APT group ChamelGang and its arsenal
The original link failed its last check. Original publisher Detailsfor Masters of Mimicry: new APT group ChamelGang and its arsenal
-
The original link failed its last check. Original publisher Detailsfor RedSense
-
report-old-dogs-new-tricks.pdf
The original link failed its last check. Original publisher Detailsfor report-old-dogs-new-tricks.pdf
-
Ryuk Ransomware Now Targeting Webservers
The original link failed its last check. Original publisher Detailsfor Ryuk Ransomware Now Targeting Webservers
-
Looks like the page you're looking for doesn't exist or has moved.
The original link failed its last check. Original publisher Detailsfor Looks like the page you're looking for doesn't exist or has moved.
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor CTIR_casestudy_2.pdf
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor CTIR_casestudy_1.pdf
-
the-operations-of-winnti-group.pdf
The original link failed its last check. Original publisher Detailsfor the-operations-of-winnti-group.pdf
-
report-bb-2021-threat-report.pdf
The original link failed its last check. Original publisher Detailsfor report-bb-2021-threat-report.pdf
-
Technical Analysis of Operation Diànxùn
The original link failed its last check. Original publisher Detailsfor Technical Analysis of Operation Diànxùn
-
CSET - Academics, AI, and APTs
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor CSET - Academics, AI, and APTs
-
Higaisa or Winnti? APT41 backdoors, old and new
The original link failed its last check. Original publisher Detailsfor Higaisa or Winnti? APT41 backdoors, old and new
-
Analyzing APT19 malware using a step-by-step method
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Analyzing APT19 malware using a step-by-step method
-
In-Memory shellcode decoding to evade AVs/EDRs
The original link failed its last check. Original publisher Detailsfor In-Memory shellcode decoding to evade AVs/EDRs
-
Catching APT41 exploiting a zero-day vulnerability
The original link failed its last check. Detailsfor Catching APT41 exploiting a zero-day vulnerability
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor [CB19] Cyber Threat Landscape in Japan – Revealing Threat in the Shadow by Chi En Shen (Ashley) Oleg Bondarenko
-
The original link failed its last check. Original publisher Detailsfor Aarhus_miniseminar_291118.pdf
-
mpressioncss_ta_report_2019.pdf
The original link failed its last check. Original publisher Detailsfor mpressioncss_ta_report_2019.pdf
-
U.S. Indicts Chinese Hacker-Spies in Conspiracy to Steal Aerospace Secrets
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor U.S. Indicts Chinese Hacker-Spies in Conspiracy to Steal Aerospace Secrets
-
US Arrests Chinese Man Involved With Sakula Malware Used in OPM and Anthem Hacks
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor US Arrests Chinese Man Involved With Sakula Malware Used in OPM and Anthem Hacks
-
Shell Crew Variants Continue to Fly Under Big AV’s Radar
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Shell Crew Variants Continue to Fly Under Big AV’s Radar
-
KingSlayer A Supply chain attack
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor KingSlayer A Supply chain attack
-
ICIT-Brief-China-Espionage-Dynasty
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor ICIT-Brief-China-Espionage-Dynasty
-
Mo' Shells Mo' Problems - Web Server Log Analysis »
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Mo' Shells Mo' Problems - Web Server Log Analysis »
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor PowerPoint Presentation
-
The Anthem Hack_ All Roads Lead to China - ThreatConnect _ Enterprise Threat Intelligence Platform
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor The Anthem Hack_ All Roads Lead to China - ThreatConnect _ Enterprise Threat Intelligence Platform
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor TA_Fidelis_Turbo_1602_0
-
Know Your Enemies 2.0: A Primer on Advanced Persistent Threat Groups
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Know Your Enemies 2.0: A Primer on Advanced Persistent Threat Groups
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor I am Ironman: DEEP PANDA Uses Sakula Malware to Target Organizations in Multiple Sectors » Adversary Manifesto
-
Sakula Reloaded » Adversary Manifesto
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Sakula Reloaded » Adversary Manifesto
-
Microsoft Word - Terracotta VPN Final 8-3.docx
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Microsoft Word - Terracotta VPN Final 8-3.docx
-
The Black Vine Cyberespionage Group
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor The Black Vine Cyberespionage Group
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor crowdstrike-deep-panda-report
-
The Anthem Hack: All Roads Lead To China
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor The Anthem Hack: All Roads Lead To China
-
The Anthem Hack: All Roads Lead to China - ThreatConnect | Enterprise Threat Intelligence Platform
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor The Anthem Hack: All Roads Lead to China - ThreatConnect | Enterprise Threat Intelligence Platform
-
The Anthem Hack- All Roads Lead to China
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor The Anthem Hack- All Roads Lead to China
-
Microsoft Word - 2015-02-XX -Scanbox II - TLPWHITE.docx
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Microsoft Word - 2015-02-XX -Scanbox II - TLPWHITE.docx
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Global Threat Intel Report
-
Anthem Breach May Have Started in April 2014
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Anthem Breach May Have Started in April 2014
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor I am Ironman: DEEP PANDA Uses Sakula Malware to Target Organizations in Multiple Sectors » Adversary Manifesto
-
I am Ironman- DEEP PANDA Uses Sakula Malware to Target Organizations in Multiple Sectors
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor I am Ironman- DEEP PANDA Uses Sakula Malware to Target Organizations in Multiple Sectors
-
Chinese hackers 'breach Australian media organisations' ahead of G20
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Chinese hackers 'breach Australian media organisations' ahead of G20
-
Deep in Thought- Chinese Targeting of National Security Think Tanks
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Deep in Thought- Chinese Targeting of National Security Think Tanks
-
Deep in Thought_ Chinese Targeting of National Security Think Tanks »
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Deep in Thought_ Chinese Targeting of National Security Think Tanks »
-
Mo' Shells Mo' Problems - Network Detection »
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Mo' Shells Mo' Problems - Network Detection »
-
Mo' Shells Mo' Problems - Deep Panda Web Shells | CrowdStrike
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Mo' Shells Mo' Problems - Deep Panda Web Shells | CrowdStrike
-
Mo' Shells Mo' Problems - File List Stacking »
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Mo' Shells Mo' Problems - File List Stacking »
-
RSA Incident Response Emerging Threat Profile: Shell Crew
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor RSA Incident Response Emerging Threat Profile: Shell Crew
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Deep Panda
Newest first. Details opens the report in Explore.