Also known as: APT2, MSUpdater, Putter Panda, PLA Unit 61486, TG-6952, Group 36, SearchFire, 4HCrew, SULPHUR, G0024
Putter Panda is a Chinese threat group that has been attributed to Unit 61486 of the 12th Bureau of the PLA’s 3rd General Staff Department (GSD). (Citation: CrowdStrike Putter Panda)
Targeted Sectors
Targeted Countries / Regions
Executive Summary
Putter Panda, a suspected Chinese state-sponsored threat group linked to PLA Unit 61486, primarily engages in espionage activities targeting critical sectors such as government, defense, technology, and aerospace. The group has been observed using sophisticated malware and attack techniques to compromise systems, likely with the aim of gathering sensitive information.
Goals & Targeting
Putter Panda's strategic objectives appear to focus on intelligence gathering and espionage, particularly targeting industries and countries that hold significant geopolitical or economic interests for China. The group's targeting of sectors like government, defense, technology, and aerospace suggests a focus on stealing sensitive information, military secrets, and advanced technologies. Given the prominence of US-based victims, Putter Panda likely seeks to undermine American strategic advantages in these areas.
Enhanced Description
Putter Panda is a cyberespionage group suspected to be associated with Unit 61486 of the Chinese People's Liberation Army (PLA). The group has been linked to several advanced persistent threat (APT) campaigns and is known for targeting high-value sectors such as government, defense, technology, and aerospace. Putter Panda's activities are likely aimed at gathering sensitive information, intellectual property, and strategic data. The group has been observed using malware frameworks such as 3PARA RAT, pngdowner, 4H RAT, and httpclient to compromise systems. These tools often involve techniques like dynamic-link library (DLL) injection, encrypted file storage, and registry modifications to maintain persistence on compromised systems.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
Putter Panda's campaigns typically involve targeted attacks against specific industries, often leveraging custom malware and long-term persistence to steal sensitive data. The group has been active for several years, with consistent improvements in their attack techniques. Notable campaigns have targeted US-based government agencies, defense contractors, and technology companies.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
High confidence in the assessment of Putter Panda as a state-sponsored Chinese threat group due to multiple credible reports and technical evidence. However, gaps exist in exact timelines and specific campaign details.
No campaigns linked yet.
No observed data linked yet.
4
Techniques
7
Tools
0
Campaigns
6
IOCs
0
Observed Data
3
Tactics