APT19__2016__Deep_in_Thought_Chinese_Targeting_of_National_Security_Think_Tanks.pdf
ID: 1f3cd8f2-7262-4f77-b484-327196b135e7
STIX ID: report--1f3cd8f2-7262-4f77-b484-327196b135e7
Threat Score
90/100
Uploaded: 2026-08-07
Published Date: 2016-05-02
Last Modified Date: 2016-05-02
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
CrowdStrike observed DEEP PANDA, a sophisticated Chinese nation-state intrusion group, conducting targeted compromises of national security think tanks using stolen credentials, webshells, and PowerShell scheduled tasks that decode and execute a .NET loader (Wafer) in memory which then typically deploys the MadHatter .NET RAT; attackers used WMI and scheduled tasks for lateral movement, compressed and encrypted targeted documents for exfiltration, and leveraged stealthy, anti-forensic techniques to avoid disk artifacts and IOCs. Falcon Host endpoint telemetry enabled real-time detection, attribution, and forensic visibility across multiple simultaneous compromises, revealing pivots in targeting tied to geopolitical events and demonstrating high operational security and persistence by the actor.
