# Aquatic Panda (Earth Lusca) APT - Log4Shell Exploitation and Multi-Platform Backdoor Campaigns Targeting 17 Countries

> China-aligned APT Aquatic Panda (aka Earth Lusca) conducts targeted intelligence collection and industrial espionage across telecommunications, government, NGOs, and academic institutions using CVE-2021-44228 (Log4Shell) and a sophisticated malware arsenal including kernel rootkits, RATs, and backdoors. Active exploitation ongoing through 2024-2025 with documented campaigns targeting 17 countries across Asia, Europe, and North America. DOJ indicted I-SOON employees and MPS officers on March 5, 2025 for 2016-2023 espionage operations.

- **Published:** 2026-06-28T00:00:00Z
- **Last reviewed:** 2026-06-28T00:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-0986
- **ID:** TL-2026-0986
- **Severity:** CRITICAL (CVSS 10)
- **Category:** VULNERABILITY
- **Status:** ACTIVE
- **Actor:** Earth Lusca (China)
- **Detections:** 9 · **IOCs:** 26 (full data via the Threadlinqs MCP server — Purple tier)
- **CVEs:** CVE-2021-44228

## Description

Aquatic Panda is a China-aligned advanced persistent threat (APT) group active since at least May 2020, focusing on intelligence collection and industrial espionage against critical infrastructure sectors. Operating under multiple aliases (Earth Lusca, TAG-22, FishMonger, BRONZE UNIVERSITY, Charcoal Typhoon, CHROMIUM, FISHMONGER, Red Dev 10, Red Scylla, RedHotel) and affiliated with the Winnti Group umbrella, the group maintains extensive C2 infrastructure (50+ servers hosted in China) for multi-platform command and control.

The group's primary exploitation vector is CVE-2021-44228 (Log4Shell), a critical remote code execution vulnerability in Apache Log4j2 with CVSS 10.0. Since the public disclosure in December 2021, this vulnerability has been actively exploited by multiple threat actors including Aquatic Panda, enabling arbitrary code execution on vulnerable Java logging services across government networks, telecommunications infrastructure, and critical sectors.

Aquatic Panda's malware arsenal includes SprySOCKS (Linux/Windows backdoor with kernel driver variants RawWNPF), ShadowPad (modular backdoor suite), BIOPASS RAT (Python-based RAT with screen capture via OBS Studio framework), KTLVdoor (obfuscated Golang multiplatform backdoor), SodaMaster, Spyder, and RPipeCommander. The RawWNPF kernel driver component hooks NtQuerySystemInformation, implements filesystem minifilter callbacks, manipulates Windows Filtering Platform (WFP) callouts to hide network connections, and enables TCP traffic diversion for stealthy command delivery.

Operation FishMedley (January-October 2022) compromised seven government, NGO, think tank, and Catholic charity targets across Taiwan, Hungary, Turkey, Thailand, United States, and France. Broader targeting spans 17 countries (2021-2023) across Asia, Europe, and North America with focus on telecommunications operators, government agencies, academic institutions, and policy analysis organizations.

Attack chain methodology includes initial access via existing privileged access (domain administrator credentials), lateral movement using Impacket-based network traversal and WMI, credential harvesting (LSASS dumping, Firefox database extraction, registry hive collection), reconnaissance (fscan/nbtscan network scanning), and data exfiltration via Dropbox integration. TTPs leverage PowerShell scripting, Base64 encoding, EDR evasion techniques, and living-off-the-land binaries.

DOJ Cyber Investigations indictment (March 5, 2025) charged I-SOON CEO Wu Haibo, COO Chen Cheng, and technical staff with conducting cyber-espionage operations (2016-2023) funded by the Chinese government. The FBI added indicted individuals to its Most Wanted Cyber Threat Actors list, confirming state-sponsored attribution with HIGH confidence.

## MITRE ATT&CK

- T1190 Exploit Public-Facing Application
- T1566 Phishing
- T1598 Phishing for Information
- T1059 Command and Scripting Interpreter
- T1210 Exploitation of Remote Services
- T1204 User Execution
- T1547 Boot or Logon Autostart Execution
- T1543 Create or Modify System Process
- T1505 Server Software Component
- T1548 Abuse Elevation Control Mechanism
- T1574 Hijack Execution Flow
- T1547 Boot or Logon Autostart Execution
- T1140 Deobfuscate/Decode Files or Information
- T1027 Obfuscated Files or Information
- T1685 Disable or Modify Tools
- T1564 Hide Artifacts
- T1033 System Owner/User Discovery
- T1078 Valid Accounts
- T1055 Process Injection
- T1003 OS Credential Dumping
- T1555 Credentials from Password Stores
- T1552 Unsecured Credentials
- T1087 Account Discovery
- T1083 File and Directory Discovery
- T1046 Network Service Discovery
- T1069 Permission Groups Discovery
- T1082 System Information Discovery
- T1016 System Network Configuration Discovery
- T1021 Remote Services
- T1550 Use Alternate Authentication Material
- T1115 Clipboard Data
- T1113 Screen Capture
- T1125 Video Capture
- T1071 Application Layer Protocol
- T1573 Encrypted Channel
- T1105 Ingress Tool Transfer
- T1571 Non-Standard Port
- T1572 Protocol Tunneling
- T1030 Data Transfer Size Limits
- T1048 Exfiltration Over Alternative Protocol

## Sources

- [Aquatic Panda (Earth Lusca) Analysis: Campaigns, Malware, and TTPs](https://www.picussecurity.com/resource/blog/aquatic-panda-earth-lusca-analysis-campaigns-malware-and-ttps)
- [China-Linked APT Aquatic Panda: 10-Month Campaign, 7 Global Targets, 5 Malware Families](https://thehackernews.com/2025/03/china-linked-apt-aquatic-panda-10-month.html)
- [CVE-2021-44228 Detail - NVD](https://nvd.nist.gov/vuln/detail/CVE-2021-44228)
- [ESET Research reveals Operation FishMedley — global espionage operation by China's FishMonger and I-SOON](https://www.eset.com/us/about/newsroom/research/eset-research-reveals-operation-fishmedley-global-espionage-operation-by-chinas-fishmonger-and-i-soon/)
- [Operation FishMedley targeting governments, NGOs, and think tanks](https://www.welivesecurity.com/en/eset-research/operation-fishmedley/)
- [ESET discovers Windows SprySOCKS variant with rootkit capabilities](https://cyberinsider.com/eset-discovers-windows-sprysocks-variant-with-rootkit-capabilities/)
- [SprySOCKS Windows Backdoor Uses Kernel Driver to Hide Processes, Files, and Network Traffic](https://gbhackers.com/sprysocks-windows-backdoor-uses-kernel/)
- [FishMonger's arsenal upgraded: SprySOCKS for Windows](https://www.welivesecurity.com/en/eset-research/fishmongers-arsenal-upgraded-sprysocks-windows/)
- [Earth Lusca Uses KTLVdoor Backdoor for Multiplatform Intrusion](https://www.trendmicro.com/en_us/research/24/i/earth-lusca-ktlvdoor.html)
- [New Cross-Platform Malware KTLVdoor Discovered in Attack on Chinese Trading Firm](https://thehackernews.com/2024/09/new-cross-platform-malware-ktlvdoor.html)
- [ShadowPad: A Masterpiece of Privately Sold Malware in Chinese Espionage](https://www.sentinelone.com/labs/shadowpad-a-masterpiece-of-privately-sold-malware-in-chinese-espionage/)
- [BIOPASS RAT Malware Targets Its Victims via Watering Hole Attacks](https://www.picussecurity.com/resource/blog/biopass-rat-malware-watering-hole-attacks)
- [BIOPASS RAT New Malware Sniffs Victims via Live Streaming](https://www.trendmicro.com/en_us/research/21/g/biopass-rat-new-malware-sniffs-victims-via-live-streaming.html)
- [Aquatic Panda - Threat Group Cards: A Threat Actor Encyclopedia](https://apt.etda.or.th/cgi-bin/showcard.cgi?g=Aquatic+Panda&n=1)
- [US charges Chinese nationals in cyberattacks on Treasury, dissidents and more](https://therecord.media/doj-charges-chinese-nationals-isoon-cyberattacks-treasury)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-0986
