
A China-linked advanced persistent threat (APT) group known as Aquatic Panda has been connected to a sophisticated espionage campaign targeting organizations across multiple countries in 2022. Dubbed “Operation FishMedley” by cybersecurity firm ESET, the campaign targeted government entities, Catholic charities, NGOs, and think tanks in Taiwan, Hungary, Turkey, Thailand, France, and the United States.
The ten-month campaign, which ran from January to October 2022, utilized malware commonly associated with Chinese threat actors, including ShadowPad, SodaMaster, and Spyder. ESET researcher Matthieu Faou noted that these implants are “common or exclusive to China-aligned threat actors.”
Aquatic Panda, also tracked under names like Bronze University, Charcoal Typhoon, Earth Lusca, and RedHotel (or FishMonger by ESET), has been active since at least 2019. The group operates under the Winnti Group umbrella (also known as APT41 or Barium) and is reportedly overseen by the Chinese contractor i-Soon, whose employees were recently charged by the U.S. Department of Justice for espionage activities conducted between 2016 and 2023.
The 2022 attacks employed five different malware families, including:
– ScatterBee: A loader used to deploy other malware
– ShadowPad: A modular backdoor
– Spyder: A specialized implant
– SodaMaster: A tool previously associated with APT10 but now potentially shared among multiple Chinese APT groups
– RPipeCommander: A previously undocumented C++ implant that functions as a reverse shell
While the initial access vector remains unknown, ESET highlighted the group’s willingness to reuse well-known malware tools even after they’ve been publicly documented and analyzed by security researchers.
