Putter Panda

MITRE ATT&CK: G0024 View on attack.mitre.org

Aliases: APT2, MSUpdater, PLA Unit 61486, PUTTER PANDA, 4HCrew, SULPHUR, SearchFire, TG-6952, Putter Panda

First seen
2007-01-01 00:00:00
Origin
CN
Primary motivation
espionage
Sophistication
advanced
Resource level
government
Actor type
Espionage
Last IoC activity
2026-07-15 20:45:03
Profile updated
2026-07-07 12:31:17

Targeted industries: defense-and-aerospace technology-and-telecommunications government-and-public-sector

Targeted regions: country_code:us country_code:jp country_code:de

Context

Putter Panda is a Chinese threat group that has been attributed to Unit 61486 of the 12th Bureau of the PLA’s 3rd General Staff Department (GSD).

Detection coverage

  • 1 YARA rules
  • 192 Sigma rules

Malware & tools used

  • Registry Run Keys / Startup Folder (attack-pattern)
  • Disable or Modify Tools (attack-pattern)
  • Dynamic-link Library Injection (attack-pattern)
  • Encrypted/Encoded File (attack-pattern)
  • 3PARA RAT (malware)
  • pngdowner (malware)
  • 4H RAT (malware)
  • httpclient (malware)

Reports & references

  • Mandiant — Apt Groups (report)
  • Mandiant — Cds19 Executive S08 Achievement Unlocked (report)
  • cdn0.vox-cdn.com — Crowdstrike Intelligence Report Putter Panda.Original (report)
  • cfr.org — Putter Panda (report)
  • MITRE ATT&CK — G0024 (report)
  • blogs.blackberry.com — Puttering Into The Future (report)

External references