← Back to all threat actors

Deep Panda

Also known as Shell Crew, WebMasters, KungFu Kittens, PinkPanther, Black Vine
Tracked as G0009

Deep Panda is a suspected Chinese threat group known to target many industries, including government, defense, financial, and telecommunications. The intrusion into healthcare company Anthem has been attributed to Deep Panda. This group is also known as Shell Crew, WebMasters, KungFu Kittens, and PinkPanther. Deep Panda also appears to be known as Black Vine based on the attribution of both group names to the Anthem intrusion. Some analysts track Deep Panda and APT19 as the same group, but it is unclear from open source information if the groups are the same.

How we source and review actor profiles
Motivation
nation-state
Status
Active

Activity timeline

A dated ledger of actor-claimed victims, campaigns, indicators, identity mappings, relationships, and CVE links. Each date states what it measures. For extensive leak-site histories, victim entries are limited to the 100 most recent distinct listings.

Cataloged
IdentityAlias: Shell Crew

Reviewed identity mapping approved on this date.

Cataloged
IdentityAlias: WebMasters

Reviewed identity mapping approved on this date.

Cataloged
IdentityAlias: KungFu Kittens

Reviewed identity mapping approved on this date.

Cataloged
IdentityAlias: PinkPanther

Reviewed identity mapping approved on this date.

Cataloged
IdentityAlias: Black Vine

Reviewed identity mapping approved on this date.

Cataloged
IdentityTracking identifier: G0009

Reviewed identity mapping approved on this date.

Identity and attribution

Exact names and tracking identifiers resolve to this canonical profile. Rebrands, affiliations, and overlapping clusters remain separate confidence-rated relationships.

Name map

Deep PandaCanonical Name
Black VineAlias
KungFu KittensAlias
PinkPantherAlias
Shell CrewAlias
WebMastersAlias
G0009Tracking Id

Loading CVEs, techniques, indicators, malware, victims, and activity...