Crowdstrike witnessed a Chinese espionage group, AQUATIC PANDA, using the Log4j bug (dubbed Log4Shell) to attack an unnamed academic institution. The Crowdstrike Falcon OverWatch team uncovered suspicious activity stemming from a Tomcat process running under a vulnerable VMWare Horizon instance at a large academic institution. The company didn’t name the institution but noted that it was able to disrupt an ‘active hands-on intrusion.’ The CrowdStrike Intelligence team linked the infrastructure used in the attempted hack to the threat actor known as AQUATIC PANDA. According to researchers, it is a China-based targeted intrusion adversary with a dual mission of intelligence collection...