Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors Putter Panda

Also known as: APT2, MSUpdater, Putter Panda, PLA Unit 61486, TG-6952, Group 36, SearchFire, 4HCrew, SULPHUR, G0024

Description

Putter Panda is a Chinese threat group that has been attributed to Unit 61486 of the 12th Bureau of the PLA’s 3rd General Staff Department (GSD). (Citation: CrowdStrike Putter Panda)

Goals & Targeting

Targeted Sectors

Government
Defense
Technology
Aerospace & defense
Research

Targeted Countries / Regions

US

AI Analysis

· 1 week ago

Executive Summary

Putter Panda, a suspected Chinese state-sponsored threat group linked to PLA Unit 61486, primarily engages in espionage activities targeting critical sectors such as government, defense, technology, and aerospace. The group has been observed using sophisticated malware and attack techniques to compromise systems, likely with the aim of gathering sensitive information.

Goals & Targeting

Putter Panda's strategic objectives appear to focus on intelligence gathering and espionage, particularly targeting industries and countries that hold significant geopolitical or economic interests for China. The group's targeting of sectors like government, defense, technology, and aerospace suggests a focus on stealing sensitive information, military secrets, and advanced technologies. Given the prominence of US-based victims, Putter Panda likely seeks to undermine American strategic advantages in these areas.

Enhanced Description

Putter Panda is a cyberespionage group suspected to be associated with Unit 61486 of the Chinese People's Liberation Army (PLA). The group has been linked to several advanced persistent threat (APT) campaigns and is known for targeting high-value sectors such as government, defense, technology, and aerospace. Putter Panda's activities are likely aimed at gathering sensitive information, intellectual property, and strategic data. The group has been observed using malware frameworks such as 3PARA RAT, pngdowner, 4H RAT, and httpclient to compromise systems. These tools often involve techniques like dynamic-link library (DLL) injection, encrypted file storage, and registry modifications to maintain persistence on compromised systems.

Key Capabilities

  • State-sponsored espionage
  • Sophisticated malware development (e.g., RATs)
  • DLL injection techniques
  • Encrypted file storage mechanisms
  • Registry and startup folder modifications
  • Disabling or modifying defensive tools

MITRE ATT&CK Tactics

Initial Access
Execution
Persistence
Defense Evasion

ATT&CK Techniques

T1055.001
T1027.013
T1547.001
T1685

Software / Tooling

3PARA RAT
pngdowner
4H RAT
httpclient

Campaigns & Victims

Putter Panda's campaigns typically involve targeted attacks against specific industries, often leveraging custom malware and long-term persistence to steal sensitive data. The group has been active for several years, with consistent improvements in their attack techniques. Notable campaigns have targeted US-based government agencies, defense contractors, and technology companies.

IOC Patterns

  • Spear-phishing emails with malicious attachments
  • DLL injection into legitimate processes
  • Encrypted files dropped during compromising operations
  • Registry entry modifications for persistence

Recommended Actions

  • Implement robust endpoint detection and response (EDR) solutions to identify and respond to Putter Panda's TTPs.
  • Monitor for unusual network activity, particularly encrypted communications that might indicate C2 channels.
  • Enhance phishing detection mechanisms to counter spear-phishing campaigns.
  • Conduct regular audits of system registries and startup folders to detect unauthorized modifications.
  • Use threat intelligence feeds to block known malicious domains and IP addresses associated with Putter Panda.

Suggested Tags

APT
espionage
government
defense
technology

Confidence Assessment

High confidence in the assessment of Putter Panda as a state-sponsored Chinese threat group due to multiple credible reports and technical evidence. However, gaps exist in exact timelines and specific campaign details.

ATT&CK Techniques

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

References

  1. CrowdStrike Putter Panda — Crowdstrike Global Intelligence Team. (2014, June 9). CrowdStrike Intelligence Report: Putter Panda. Retrieved January 22, 2016.
  2. Cylance Putter Panda — Gross, J. and Walter, J.. (2016, January 12). Puttering into the Future.... Retrieved November 17, 2024.

Intel Summary

4

Techniques

7

Tools

0

Campaigns

6

IOCs

0

Observed Data

3

Tactics

Tags

APT
espionage
government
defense
technology

Details

MITRE ID
G0024
Type
Unknown
Resource Level
Government
Primary Motivation
Espionage
Country of Origin
China (CN)
Confidence
90%
Added
May 2, 2026
STIX ID
intrusion-set--5ce5392a-3a6c-4e07-9df3-9b6a9159ac45
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.