Chinese hackers Aquatic Panda were linked to a “global cyberespionage” that took place in 2022 targeting seven organizations.

Targets included governments, Catholic charities, non-governmental organizations (NGOs), and think tanks in Taiwan, Hungary, Turkey, Thailand, France, and the United States. According to ESET, the malicious campaign took place over a 10-month period between January and October 2022.
The Aquatic Panda hackers used implants, such as ShadowPad, SodaMaster , and Spyder, which have generally been linked to China.
See also: Chinese hackers MirrorFace target victims with ANEL and AsyncRAT
Aquatic Panda is also known as Bronze University, Charcoal Typhoon, Earth Lusca, and RedHotel and is a cyberespionage group from China that has been active since at least 2019. ESET tracks the group as FishMonger.
Cyberespionage attacks in 2022 are characterized by the use of five different malware families:
- ScatterBee loader
- ShadowPad
- Spyder
- SodaMaster
- RPipeCommander
Researchers are unsure how initial access to target systems is achieved.
SodaMaster was originally used by the APT10, but its use in cyberespionage attacks suggests that it may be used by many Chinese APT groups.
See also: Chinese hackers target Juniper Networks routers
RPipeCommander, another C++ implant used by Chinese hackers Aquatic Panda, was deployed against a government agency in Thailand. It acts as a reverse shell that can execute commands (using cmd.exe) and collect outputs.

Chinese hackers pose a significant threat to organizations and governments around the world with highly adaptive techniques and use of advanced espionage tools.
See also: North Korean hackers “uploaded” spyware to Google Play
The 2022 attacks by Chinese hackers Aquatic Panda serve as a reminder of the ongoing threat posed by such cyber espionage campaigns and the need for enhanced cybersecurity measures. It is vital that government agencies and organizations remain vigilant and take the necessary steps to defenses cybersecurity. It is important for organizations to regularly update their systems, implement strong security measures, and educate employees about new threats.
At the same time, cooperation between countries to share information and implement strong security protocols can also help mitigate the risk of such attacks.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
Source: thehackernews.com
