Deploy autonomous AI agents that reason, exploit, and validate complex vulnerability chains — not another scanner, an agentic system that thinks like a senior pentester.
Also known as: Turbine Panda, APT 26, Shell Crew, WebMasters, KungFu Kittens, Group 13, PinkPanther, Black Vine, Bronze Express, JerseyMikes, Taffeta Typhoon, TURBINE PANDA, BRONZE EXPRESS, TECHNETIUM
During recent engagements, the RSA IR Team has responded to multiple incidents involving a common adversary targeting each client’s infrastructure and assets. The RSA IR Team is referring to this threat group internally as “Shell_Crew”; however, they are also referred to as Deep Panda, WebMasters, KungFu Kittens, SportsFans, and PinkPanther amongst the security community. Some analysts track Turbine Panda, DarkHydrus, LazyMeerkat and APT 19, Deep Panda, C0d0so0 as the same group, but it is unclear from open source information if the groups are the same. Turbine Panda has some overlap with Emissary Panda, APT 27, LuckyMouse, Bronze Union .
No exploited CVEs have been attributed to this threat actor yet.
Browse CVE Database