Gold Open Source
ExplorePackagesVulnerabilitiesCWEsMCP ServersScan
Login
Gold Open Source

The authoritative source for production-ready open-source components. Every package, container image, AI model, and MCP server undergoes rigorous verification for security, malware, and license compliance.

Explore Gold

  • Explore Everything
  • Packages
  • Gold Certified Packages
  • Container Images
  • AI Models
  • MCP Servers
  • Agent Skills
  • Chip Manufacturers

Security Data & Tools

  • Scan Your Dependencies
  • Trending Threats
  • Threat RSS Feeds
  • CVE Database
  • Actively Exploited (KEV)
  • SGZ Zero-Days
  • CWE Index
  • MITRE ATT&CK
  • Malicious Packages
  • Security Glossary
  • Supply-Chain Report
  • Developers (API & Badge)
  • Chrome Extension
  • Credits & Data Sources

Products

  • The Platform
  • ESSCM
  • Portal
  • TPRM
  • OSM
  • Cowork
  • Code / Runner
  • Guard

Use Cases

  • Know Your Software
  • Auto-Fix Vulnerabilities
  • Asset Discovery
  • AI Governance
  • MCP Server Security
  • Supply Chain Compliance
  • Zero-Day Discovery
  • All Use Cases

Company

  • About
  • Pricing
  • Blog
  • Documentation
  • Safeguard Academy
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 Gold Open Source. All rights reserved.

Built with care bySafeguard
Home/ATT&CK/Groups/G0143
MITRE ATT&CK Group

Aquatic Panda (G0143)

ShareXLinkedInRedditHN

[Aquatic Panda](https://attack.mitre.org/groups/G0143) is a suspected China-based threat group with a dual mission of intelligence collection and industrial espionage. Active since at least May 2020, [Aquatic Panda](https://attack.mitre.org/groups/G0143) has primarily targeted entities in the telecommunications, technology, and government sectors.(Citation: CrowdStrike AQUATIC PANDA December 2021)

▪Techniques used (35)

T1027.010Command ObfuscationT1087Account DiscoveryT1070.004File DeletionT1059.004Unix ShellT1021.002SMB/Windows Admin SharesT1036.004Masquerade Task or ServiceT1574.006Dynamic Linker HijackingT1070.003Clear Command HistoryT1543.003Windows ServiceT1550.002Pass the HashT1574.001DLLT1021.001Remote Desktop ProtocolT1005Data from Local SystemT1105Ingress Tool TransferT1007System Service DiscoveryT1654Log EnumerationT1021.004SSHT1112Modify RegistryT1036.005Match Legitimate Resource Name or LocationT1588.001MalwareT1518.001Security Software DiscoveryT1059.003Windows Command ShellT1685Disable or Modify ToolsT1033System Owner/User DiscoveryT1047Windows Management InstrumentationT1588.002ToolT1595.002Vulnerability ScanningT1003.001LSASS MemoryT1021Remote ServicesT1082System Information DiscoveryT1218.011Rundll32T1685.005Clear Windows Event LogsT1078.002Domain AccountsT1560.001Archive via UtilityT1059.001PowerShell

▪Software used (6)

S0645WevtutiltoolS0141Winnti for WindowsmalwareS0385njRATmalwareS0154Cobalt StrikemalwareS0596ShadowPadmalwareS0430Winnti for Linuxmalware
G0143on MITRE ATT&CK →

MITRE ATT&CK® is a registered trademark of The MITRE Corporation. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation.