Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors Pitty Tiger

Also known as: Pitty Panda, Pitty Tiger, Links to Skyipot, Comment Crew, Mirage, VIXEN PANDA, Ke3Chang, Playful Dragon, Metushy, Lurid, Social Network Team, Royal APT, BRONZE PALACE, BRONZE DAVENPORT, BRONZE IDLEWOOD, NICKEL, G0004, Red Vulture, Nylon Typhoon, PITTY PANDA, G0011, Temp.Pittytiger, has, APT24 has been observed, tracked as, the Newscaster Team, the Cozy Bear, Sandworm Team, Operation Cleaver, Shell Crew, WebMasters, KungFu Kittens, PinkPanther, a separate entity, APT28, VOLTZITE, for follow-on operations, APT24

Description

Pitty Tiger operates under multiple aliases that reflect both internal and external naming conventions; the most widely recognized designation is APT24. The actor utilizes an advanced, custom malware stack that centers on the PittyTiger binary and its derivative Paladin RAT to establish persistent footholds on compromised assets. By combining spear‑phishing campaigns with exploitation of known Office document vulnerabilities, the group can bypass perimeter defenses and rapidly deploy its code base. Beyond initial infection, Pitty Tiger emphasizes credential harvesting and lateral movement via valid accounts, frequently leveraging tools such as Mimikatz and gsecdump to elevate privileges. The attacker’s infrastructure is distributed across multiple C2 domains, many of which use temporary or obfuscated suffixes that complicate detection efforts. Public analyses from Airbus, FireEye, and CrowdStrike associate the threat actor with mainland China, while some references note opportunistic exploitation of vendors supplying services to rival customers. Despite this ambiguity, the breadth of sector coverage and the pattern of sophisticated custom malware deployment strongly suggest a strategic intelligence program rather than purely commercial or vandalistic motives.

Goals & Targeting

Targeted Sectors

Government
Financial services
Telecommunications
Defense
Healthcare
Education
Manufacturing
Media
Non profit
Energy
Critical infrastructure
Pharmaceutical
Aviation
Hospitality
Aerospace
Retail
Information technology
Think tank
Transportation
Mining
Chemical
Gaming
Legal services
Nuclear
Entertainment
Oil gas
Maritime
Construction
Utilities

Targeted Countries / Regions

IN
US
CN
RU
IL
IR
VN
JP
GB
AU
SA
PK
TW
AE
UA
SG
KR
DE
BY
TR
MX
ES
PL
CA
RO
FR
NG
KP
IT
LB
AZ
KZ

AI Analysis

Grounded in web research
· analyzed in 2 chunks · 5 hours ago

Executive Summary

Pitty Tiger, also cataloged as APT24, is a Chinese nation‑state adversary active since at least 2011. The group focuses on spear‑phishing campaigns that deploy custom malware—including PittyTiger and Paladin RAT—to infiltrate a wide range of sectors such as government, defense, telecommunications, finance, and energy across dozens of countries. Its primary objective appears to be geopolitical intelligence collection while monetizing services for competitors.

Goals & Targeting

The strategic objective of Pitty Tiger is to acquire high‑value geopolitical and economic intelligence by infiltrating entities that manage critical infrastructure or sensitive governmental data. While the actor maintains a broad sector focus—government, defense, telecommunications, finance, energy, healthcare, among others—it exhibits a preference for organizations with rich informational assets that can be leveraged for both espionage and commoditization of stolen data to rival parties. The targeting profile indicates an opportunistic approach: initial attacks are often spear‑phishing campaigns against private firms or government contractors, followed by exploitation of known software CVEs. Once inside a network, the group seeks legitimate credentials to move laterally and establish persistence before exfiltrating classified or commercially valuable information.

Enhanced Description

Key Capabilities

  • Custom malware development
  • Spear phishing via email
  • Command and Control server operation

MITRE ATT&CK Tactics

Initial Access
Credential Access

ATT&CK Techniques

T1078
T1588
T1566.001

Software / Tooling

Machete
Regin
Akira
Carbanak
PoisonIvy
Octopus
AppleJeus
Mimikatz
gsecdump
Turla
Winnti
Cobalt
Mirage
PittyTiger
Paladin RAT
Dark
Medusa
Nexus
SideWinder
Poseidon
OilRig
Guard
Aurora
BADAUDIO
BlackByte
BrutPOS
Confucius
DarkHotel
Karma
Kimsuky
Naikon
paladin
PLAY
RedCurl
Void
GitHub
Remote access tools
APT38
Moonstone Sleet
BARIUM
Trojan
Hafnium
Infostealer
MuddyWater

Campaigns & Victims

Pitty Tiger demonstrates a predictable operational tempo characterized by periodic spear‑phishing pushes followed by rapid deployment of custom RATs that remain unknown to mainstream anti‑malware signatures. Victims tend to be medium–to‑large enterprises situated in politically sensitive regions, with campaigns tailored to exploit both social engineering weaknesses and unpatched Office document vulnerabilities. The actor often repeats similar domain naming patterns across campaigns—using short, suffix‑heavy “TEMP.” domains—which aids in automated detection but also signals a high level of adaptability. Historical activity suggests an early 2010s inception, with a focus on expanding its footprint in critical sectors while occasionally monetizing stolen credentials or data. Notable past operations include exploit chains that leveraged known CVEs such as MS17‑010 and Office document macro vulnerabilities, all coordinated through a distributed C2 infrastructure that resists takedown efforts.

IOC Patterns

  • Spear Phishing via Email
  • Exploits multiple Word vulnerabilities
  • Custom malware activity
  • C2 server domain patterns

Recommended Actions

  • Implement organization‑wide spear‑phishing detection and user training programs to reduce successful credential compromise. Deploy end‑point detection and response (EDR) solutions capable of detecting known PittyTiger/Paladın RAT signatures or behavioral indicators of custom RATs. Enforce strict patch management for Office products, ensuring that critical CVEs—including those enabling Word macro exploitation—are promptly addressed. Monitor DNS logs for suspect “TEMP.” domain registrations and implement automated blocking mechanisms. Mandate multi‑factor authentication (MFA) on all privileged accounts to mitigate the risk of credential reuse via valid account techniques.

Suggested Tags

PittyTiger
APT24
Chinese APT
Custom Malware
Spear Phishing
Defense sector targeting
Telecommunications targeting
Opportunistic attacker
Espionage
Nation‑state threat actor

Confidence Assessment

The confidence in identifying Pitty Tiger as a Chinese state‑aligned actor is moderate to high, based on corroborating reports from reputable vendors such as Airbus and FireEye. However, gaps remain regarding the exact attribution chain (e.g., definitive malware hashes linked to specific campaigns) and precise operational timelines. Additional information on their full scope of tools, supply‑chain tactics, and insider cooperation would strengthen confidence further.

ATT&CK Techniques

Initial Access
1 technique
Resource Development
1 technique
Stealth
1 technique

Software / Tooling

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

SHA-256 Hash 7 Domain 12 Email Address 1

References

  1. attack.mitre.org — Cited by web research for: Sandworm Team
  2. attack.mitre.org — Cited by web research for: T1588
  3. apt.etda.or.th — Cited by web research for: phishing
  4. blog.talosintelligence.com — Cited by web research for: Regin
  5. http://blog.cassidiancybersecurity.com/post/2014/07/The-Eye-of-the-Tiger2 — Cited by AI analysis.
  6. https://securingtomorrow.mcafee.com/other-blogs/mcafee-labs/targeted-attacks-on-french-company-exploit-multiple-word-vulnerabilities/ — Cited by AI analysis.

Intel Summary

3

Techniques

48

Tools

0

Campaigns

21

IOCs

0

Observed Data

3

Tactics

Tags

PittyTiger
APT24
Chinese APT
Custom Malware
Spear Phishing
Defense sector targeting
Telecommunications targeting
Opportunistic attacker
Espionage
Nation‑state threat actor

Details

Type
Nation-State
Resource Level
Government
Primary Motivation
Espionage
Country of Origin
China (CN)
Confidence
70%
Added
Jul 21, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.