Aquatic Panda is an apt_group tracked by ThreatCluster, appearing in 4 threat clusters built from 7 intelligence report mentions.
Aquatic Panda is a apt_group tracked across 4 threat clusters and 7 intelligence report mentions on ThreatCluster. First observed April 22, 2026; most recent activity July 4, 2026.
ESET researchers have identified two new Windows variants of the SprySOCKS backdoor, previously exclusive to Linux, attributed to the Chinese cyberespionage group FishMonger. The variants, labeled WIN_DRV and WIN_PLUS,…
Adversaries are increasingly leveraging external remote services like VPNs and Citrix to gain unauthorized access to networks. These attacks often involve using valid accounts obtained through credential harvesting or…
Recent reports detail the tactics employed by various cyber adversaries to enumerate files and directories on compromised systems. Adversaries utilize command shell utilities and custom tools to gather sensitive…
The ATT&CK framework has released version 19, which includes significant updates to its structure and coverage. Notably, the Defense Evasion Tactic has been split into two distinct categories: Stealth and Defense…
Aquatic Panda is an apt_group tracked by ThreatCluster, appearing in 4 threat clusters built from 7 intelligence report mentions.
The most recent intelligence report mentioning Aquatic Panda on ThreatCluster is dated July 4, 2026. Activity was first observed April 22, 2026, giving a tracked span from then to July 4, 2026.
Across ThreatCluster reporting, Aquatic Panda most frequently co-occurs with Agrius, APT1, Apt28, Apt29, APT3, among 12 tracked related entities.
The most significant recent cluster is “FishMonger Expands SprySOCKS Malware to Windows with Kernel-Level Stealth” (12 articles · Updated June 16, 2026). Aquatic Panda appears across 4 threat clusters in total, listed above with sources.
Aquatic Panda appears in 7 intelligence report mentions across 4 deduplicated threat clusters, aggregated from 17,000+ monitored sources.