logo

APT19__2016__Deep_in_Thought_Chinese_Targeting_of_National_Security_Think_Tanks.pdf

ID: 1f3cd8f2-7262-4f77-b484-327196b135e7

STIX ID: report--1f3cd8f2-7262-4f77-b484-327196b135e7

Threat Score

90/100

Uploaded: 2026-08-07

Published Date: 2016-05-02

Last Modified Date: 2016-05-02

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
CrowdStrike observed DEEP PANDA, a sophisticated Chinese nation-state intrusion group, conducting targeted compromises of national security think tanks using stolen credentials, webshells, and PowerShell scheduled tasks that decode and execute a .NET loader (Wafer) in memory which then typically deploys the MadHatter .NET RAT; attackers used WMI and scheduled tasks for lateral movement, compressed and encrypted targeted documents for exfiltration, and leveraged stealthy, anti-forensic techniques to avoid disk artifacts and IOCs. Falcon Host endpoint telemetry enabled real-time detection, attribution, and forensic visibility across multiple simultaneous compromises, revealing pivots in targeting tied to geopolitical events and demonstrating high operational security and persistence by the actor.