Threat reportVulnerabilityTL-2026-0986

Aquatic Panda (Earth Lusca) APT - Log4Shell Exploitation and Multi-Platform Backdoor Campaigns Targeting 17 Countries

criticalACTIVE

Aquatic Panda (Earth Lusca) APT (TL-2026-0986), also tracked as Operation FishMedley, is a critical-severity software vulnerability scored CVSS 10, first published 2026-06-28. It is attributed to Earth Lusca (China) with high confidence, affects Apache Log4j2, references 1 CVE (CVE-2021-44228), maps to 41 MITRE ATT&CK techniques (T1003, T1016, T1021), and is covered by 9 detection rules and 26 indicators of compromise.

CVSS
10/10Critical
CVEs
1Referenced vulnerabilities
Techniques
41MITRE ATT&CK
Actors
2Earth Lusca
Detection rules
9SPL · KQL · Sigma
IOCs
26Indicators of compromise

Key facts for TL-2026-0986

Threat ID
TL-2026-0986
Also known as
Operation FishMedley, Log4Shell Aquatic Panda Campaign, SprySOCKS Multiplatform Backdoor Campaign, Winnti Group / Aquatic Panda Joint Operations
Severity
CRITICAL
CVSS
10 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H)
Status
ACTIVE
Category
VULNERABILITY
First published
Last reviewed
Attribution
Earth Lusca, Houndstooth Typhoon
Attribution confidence
HIGH
Nation-state nexus
China
Motivation
ESPIONAGE
Target sectors
telecoms, government administration, critical-infrastructure, finance, technology, energy, health, academia, think tanks, ngo, cryptocurrency-trading, defense-contractors
Target regions
taiwan, hong kong, thailand, pakistan, vietnam, philippines, indonesia, malaysia, singapore, hungary, turkey, france
Detection rules
9
Indicators of compromise
26

Malware and tooling in Aquatic Panda (Earth Lusca) APT

Malware and tooling: BIOPASS RAT, KTLVdoor (ELF), RPipeCommander, RawWNPF, ShadowPad, SodaMaster, SprySOCKS, Spyder, Brute Ratel C4 - S1063, Cobalt Strike, Impacket - S0357, NBTScan

How Aquatic Panda (Earth Lusca) APT works

China-aligned APT Aquatic Panda (aka Earth Lusca) conducts targeted intelligence collection and industrial espionage across telecommunications, government, NGOs, and academic institutions using CVE-2021-44228 (Log4Shell) and a sophisticated malware arsenal including kernel rootkits, RATs, and backdoors. Active exploitation ongoing through 2024-2025 with documented campaigns targeting 17 countries across Asia, Europe, and North America. DOJ indicted I-SOON employees and MPS officers on March 5, 2025 for 2016-2023 espionage operations.

Aquatic Panda is a China-aligned advanced persistent threat (APT) group active since at least May 2020, focusing on intelligence collection and industrial espionage against critical infrastructure sectors. Operating under multiple aliases (Earth Lusca, TAG-22, FishMonger, BRONZE UNIVERSITY, Charcoal Typhoon, CHROMIUM, FISHMONGER, Red Dev 10, Red Scylla, RedHotel) and affiliated with the Winnti Group umbrella, the group maintains extensive C2 infrastructure (50+ servers hosted in China) for multi-platform command and control.

The group's primary exploitation vector is CVE-2021-44228 (Log4Shell), a critical remote code execution vulnerability in Apache Log4j2 with CVSS 10.0. Since the public disclosure in December 2021, this vulnerability has been actively exploited by multiple threat actors including Aquatic Panda, enabling arbitrary code execution on vulnerable Java logging services across government networks, telecommunications infrastructure, and critical sectors.

Aquatic Panda's malware arsenal includes SprySOCKS (Linux/Windows backdoor with kernel driver variants RawWNPF), ShadowPad (modular backdoor suite), BIOPASS RAT (Python-based RAT with screen capture via OBS Studio framework), KTLVdoor (obfuscated Golang multiplatform backdoor), SodaMaster, Spyder, and RPipeCommander. The RawWNPF kernel driver component hooks NtQuerySystemInformation, implements filesystem minifilter callbacks, manipulates Windows Filtering Platform (WFP) callouts to hide network connections, and enables TCP traffic diversion for stealthy command delivery.

Operation FishMedley (January-October 2022) compromised seven government, NGO, think tank, and Catholic charity targets across Taiwan, Hungary, Turkey, Thailand, United States, and France. Broader targeting spans 17 countries (2021-2023) across Asia, Europe, and North America with focus on telecommunications operators, government agencies, academic institutions, and policy analysis organizations.

Attack chain methodology includes initial access via existing privileged access (domain administrator credentials), lateral movement using Impacket-based network traversal and WMI, credential harvesting (LSASS dumping, Firefox database extraction, registry hive collection), reconnaissance (fscan/nbtscan network scanning), and data exfiltration via Dropbox integration. TTPs leverage PowerShell scripting, Base64 encoding, EDR evasion techniques, and living-off-the-land binaries.

DOJ Cyber Investigations indictment (March 5, 2025) charged I-SOON CEO Wu Haibo, COO Chen Cheng, and technical staff with conducting cyber-espionage operations (2016-2023) funded by the Chinese government. The FBI added indicted individuals to its Most Wanted Cyber Threat Actors list, confirming state-sponsored attribution with HIGH confidence.

MITRE ATT&CK techniques used in TL-2026-0986

Credential Access

T1003 OS Credential Dumping; T1552 Unsecured Credentials; T1555 Credentials from Password Stores

Discovery

T1016 System Network Configuration Discovery; T1046 Network Service Discovery; T1069 Permission Groups Discovery; T1082 System Information Discovery; T1083 File and Directory Discovery; T1087 Account Discovery

Lateral Movement

T1021 Remote Services; T1550 Use Alternate Authentication Material

Defense Evasion

T1027 Obfuscated Files or Information; T1055 Process Injection; T1078 Valid Accounts; T1140 Deobfuscate/Decode Files or Information; T1564 Hide Artifacts

Exfiltration

T1030 Data Transfer Size Limits; T1041 Exfiltration Over C2 Channel; T1048 Exfiltration Over Alternative Protocol

discovery

T1033 System Owner/User Discovery

Execution

T1059 Command and Scripting Interpreter; T1204 User Execution

Command and Control

T1071 Application Layer Protocol; T1105 Ingress Tool Transfer; T1571 Non-Standard Port; T1572 Protocol Tunneling; T1573 Encrypted Channel

Collection

T1113 Screen Capture; T1115 Clipboard Data; T1125 Video Capture

Initial Access

T1190 Exploit Public-Facing Application; T1566 Phishing

lateral-movement

T1210 Exploitation of Remote Services

Impact

T1485 Data Destruction

Persistence

T1505 Server Software Component; T1543 Create or Modify System Process; T1547 Boot or Logon Autostart Execution

Privilege Escalation

T1547 Boot or Logon Autostart Execution; T1548 Abuse Elevation Control Mechanism

stealth

T1574 Hijack Execution Flow

reconnaissance

T1598 Phishing for Information

defense-impairment

T1685 Disable or Modify Tools

Affected products and versions in Aquatic Panda (Earth Lusca) APT

  • Apache — Log4j2
    Vulnerable versions: 2.0-beta9 through 2.15.0 (except patched 2.12.2, 2.12.3, 2.13.3, 2.14.1)
    Fixed in: 2.16.0 (JNDI feature removed); 2.12.2 (patched legacy); 2.13.3 (patched legacy); 2.14.1 (patched legacy); 2.15.0 (patched legacy)
  • Microsoft — Windows Server (all versions)
    Vulnerable versions: All versions susceptible to SprySOCKS, RawWNPF kernel driver, BIOPASS RAT, KTLVdoor deployment
    Fixed in: Windows Defender kernel-mode driver enforcement recommended; Secure Boot + UEFI driver signing enforcement
  • Linux/Unix (all distributions) — All Linux distributions
    Vulnerable versions: All versions susceptible to SprySOCKS Linux variant, KTLVdoor Linux variant
    Fixed in: Mitigated via kernel module allow-listing and SELinux/AppArmor enforcement
  • Multi-vendor — Java-based applications using Log4j2
    Vulnerable versions: Cisco products; VMware vCenter, vSphere; NetApp Data ONTAP, StorageGRID; Siemens SCADA/ICS products; Oracle WebLogic, Exadata, Identity Management; Atlassian Jira, Confluence; Elastic Stack (ELK); Kubernetes logging components; IBM WebSphere
    Fixed in: Vendor-specific Log4j2 updates and patches

Remediation for Aquatic Panda (Earth Lusca) APT

Patches

  • Apache Log4j2: Upgrade to 2.16.0 (complete JNDI removal) or apply patches 2.12.2, 2.13.3, 2.14.1, 2.15.0 for legacy versions
  • All downstream products: Apply vendor-specific patches for Log4j2 dependencies (Cisco, VMware, NetApp, Siemens, Oracle, Apache products, etc.)
  • Windows: Apply latest security updates for Windows Filtering Platform (WFP), kernel-mode driver signing, and LSASS protection

Immediate actions

  • Block C2 IOC ranges: 213.59.118.124, 61.238.103.165, 162.33.178.23, 78.141.202.70, 192.46.223.211, 168.100.10.136 at perimeter firewalls
  • Hunt for Log4j2 exploitation indicators (JNDI payloads, RCE attempts) in application logs, WAF logs, and network traffic
  • Disable Log4j JNDI lookup feature in all Java applications; upgrade to patched versions (2.16.0+ or patched legacy 2.12.2/2.13.3/2.14.1/2.15.0)
  • Scan for presence of SprySOCKS, RawWNPF kernel drivers, ShadowPad, KTLVdoor, BIOPASS RAT artifacts using YARA rules and memory forensics
  • Isolate and forensically image systems showing indicators of SprySOCKS or RawWNPF installation (process hiding, file hiding, network masking)

Workarounds

  • Disable JNDI lookups by setting log4j2.formatMsgNoLookups=true in all Log4j2 configurations
  • Remove JndiLookup class from classpath if Log4j version cannot be upgraded immediately (log4j-core-*.jar/org/apache/logging/log4j/core/lookup/JndiLookup.class)
  • Implement WAF/IDS rules to block JNDI LDAP/RMI payload patterns (${jndi:ldap:// ${jndi:rmi://)
  • Restrict outbound LDAP/RMI protocols at network boundary to prevent JNDI callback exploitation

Longer-term hardening

  • Deploy kernel-mode Driver Block rules for unsigned drivers and implement Secure Boot/UEFI Secure Boot enforcement
  • Implement EDR solutions with behavioral detection for process hollowing, registry callback hooking, minifilter driver installation, and WFP callout manipulation
  • Enforce application allow-listing with kernel-enforced policies to prevent unsigned executable and DLL execution
  • Deploy host-based firewall rules to block outbound connections to known Chinese IP ranges and RDNS patterns matching observed C2 infrastructure
  • Establish LSASS protection (Credential Guard) and enable Advanced Threat Protection (ATP) for credential access detection
  • Implement network segmentation isolating telecommunications, government, and critical infrastructure from general internet access
  • Deploy behavior-based detection for Impacket usage, WMIC lateral movement, and scheduled task creation patterns

CVEs associated with Aquatic Panda (Earth Lusca) APT

CVE-2021-44228

Weaknesses (CWE) in Aquatic Panda (Earth Lusca) APT

CWE-917, CWE-20, CWE-400, CWE-502, CWE-269, CWE-78, CWE-94

Timeline of Aquatic Panda (Earth Lusca) APT

  • Aquatic Panda (Earth Lusca) APT group first observed conducting intelligence collection and industrial espionage campaigns.
  • CVE-2021-44228 (Log4Shell) privately disclosed to Apache by Chen Zhaojun (Alibaba Cloud). Critical JNDI RCE vulnerability in Log4j2 versions 2.0-beta9 through 2.15.0.
  • CVE-2021-44228 (Log4Shell) publicly disclosed. CVSS 10.0 critical rating assigned. Proof-of-concept code rapidly distributed worldwide.
  • CISA adds CVE-2021-44228 to Known Exploited Vulnerabilities (KEV) Catalog with emergency remediation deadline of December 24, 2021.
  • Major spike in Log4Shell exploitation attempts observed across internet. 125,894,944 hits targeting CVE-2021-44228 recorded between December 10, 2021 and February 2, 2022.
  • New Year spike in Log4Shell exploitation activity. Scanning activity originating from 156 distinct ASNs begins consolidating into structured, organized campaigns.
  • Operation FishMedley campaign begins. First target (Taiwan government entity) compromised by FishMonger/Aquatic Panda using existing privileged access and Log4j exploitation vectors.
  • Operation FishMedley expands. Hungary-based Catholic organization compromised. Turkey-based entity targeted. FishMonger deploys ShadowPad, Spyder, SodaMaster across targets.
  • Thailand government entity compromised as part of Operation FishMedley. Attackers establish persistent access via ShadowPad C2 infrastructure (api.googleauthenticatoronline.com).
  • US-based Catholic charity compromised in Operation FishMedley. Second US organization (Asia-focused NGO) targeted in June 2022, followed by France think tank in October 2022.
  • Operation FishMedley concludes. Seven government, NGO, think tank, and charity targets across 6 countries compromised over 10-month campaign (Jan-Oct 2022). Deep persistent access established.
  • ESET discovers Windows variants of SprySOCKS backdoor (WIN_DRV and WIN_PLUS) deployed against government organizations in Taiwan, Thailand, Pakistan, Honduras since 2023.
  • RawWNPF kernel driver component of SprySOCKS Windows variant documented. Rootkit hooks NtQuerySystemInformation, implements minifilter callbacks, manipulates WFP callouts for network hiding.
  • Earth Lusca uses Chinese-Taiwanese geopolitical relations as social engineering lure targeting Taiwan entities ahead of national elections.
  • KTLVdoor multiplatform backdoor discovered in attack on Chinese trading company. Golang-based malware targets Windows and Linux, supports multiple reconnaissance commands (ScanTCP, ScanRDP, ScanWeb).
  • Aquatic Panda/Earth Lusca continues active exploitation through 2024. 50+ C2 infrastructure servers active, primarily in China. Group maintains operational capability across all malware families.
  • US Department of Justice unseals indictment against I-SOON employees (CEO Wu Haibo, COO Chen Cheng, technical staff) and China's Ministry of Public Security officers for conducting cyber-espionage (2016-2023). FBI adds individuals to Most Wanted Cyber Threat Actors list.

Sources cited for Aquatic Panda (Earth Lusca) APT

Detection coverage for TL-2026-0986

As of 2026-06-28, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0986 across Splunk SPL, Microsoft KQL and Sigma, covering 26 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
26 indicators of compromise · Red and above. Compare plans

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats