Putter Panda
MITRE ATT&CK: G0024 View on attack.mitre.org
Aliases: APT2, MSUpdater, PLA Unit 61486, PUTTER PANDA, 4HCrew, SULPHUR, SearchFire, TG-6952, Putter Panda
- First seen
- 2007-01-01 00:00:00
- Origin
- CN
- Primary motivation
- espionage
- Sophistication
- advanced
- Resource level
- government
- Actor type
- Espionage
- Last IoC activity
- 2026-07-15 20:45:03
- Profile updated
- 2026-07-07 12:31:17
Targeted industries: defense-and-aerospace technology-and-telecommunications government-and-public-sector
Targeted regions: country_code:us country_code:jp country_code:de
Context
Putter Panda is a Chinese threat group that has been attributed to Unit 61486 of the 12th Bureau of the PLA’s 3rd General Staff Department (GSD).
Detection coverage
- 1 YARA rules
- 192 Sigma rules
Malware & tools used
- Registry Run Keys / Startup Folder (attack-pattern)
- Disable or Modify Tools (attack-pattern)
- Dynamic-link Library Injection (attack-pattern)
- Encrypted/Encoded File (attack-pattern)
- 3PARA RAT (malware)
- pngdowner (malware)
- 4H RAT (malware)
- httpclient (malware)
Reports & references
- Mandiant — Apt Groups (report)
- Mandiant — Cds19 Executive S08 Achievement Unlocked (report)
- cdn0.vox-cdn.com — Crowdstrike Intelligence Report Putter Panda.Original (report)
- cfr.org — Putter Panda (report)
- MITRE ATT&CK — G0024 (report)
- blogs.blackberry.com — Puttering Into The Future (report)
External references
- mitre-attack — G0024
- MSUpdater
- Putter Panda
- APT2
- CrowdStrike Putter Panda
- Cylance Putter Panda
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy