Also known as: Pitty Panda, Pitty Tiger, Links to Skyipot, Comment Crew, Mirage, VIXEN PANDA, Ke3Chang, Playful Dragon, Metushy, Lurid, Social Network Team, Royal APT, BRONZE PALACE, BRONZE DAVENPORT, BRONZE IDLEWOOD, NICKEL, G0004, Red Vulture, Nylon Typhoon, PITTY PANDA, G0011, Temp.Pittytiger, has, APT24 has been observed, tracked as, the Newscaster Team, the Cozy Bear, Sandworm Team, Operation Cleaver, Shell Crew, WebMasters, KungFu Kittens, PinkPanther, a separate entity, APT28, VOLTZITE, for follow-on operations, APT24
Pitty Tiger operates under multiple aliases that reflect both internal and external naming conventions; the most widely recognized designation is APT24. The actor utilizes an advanced, custom malware stack that centers on the PittyTiger binary and its derivative Paladin RAT to establish persistent footholds on compromised assets. By combining spear‑phishing campaigns with exploitation of known Office document vulnerabilities, the group can bypass perimeter defenses and rapidly deploy its code base. Beyond initial infection, Pitty Tiger emphasizes credential harvesting and lateral movement via valid accounts, frequently leveraging tools such as Mimikatz and gsecdump to elevate privileges. The attacker’s infrastructure is distributed across multiple C2 domains, many of which use temporary or obfuscated suffixes that complicate detection efforts. Public analyses from Airbus, FireEye, and CrowdStrike associate the threat actor with mainland China, while some references note opportunistic exploitation of vendors supplying services to rival customers. Despite this ambiguity, the breadth of sector coverage and the pattern of sophisticated custom malware deployment strongly suggest a strategic intelligence program rather than purely commercial or vandalistic motives.
Targeted Sectors
Targeted Countries / Regions
Executive Summary
Pitty Tiger, also cataloged as APT24, is a Chinese nation‑state adversary active since at least 2011. The group focuses on spear‑phishing campaigns that deploy custom malware—including PittyTiger and Paladin RAT—to infiltrate a wide range of sectors such as government, defense, telecommunications, finance, and energy across dozens of countries. Its primary objective appears to be geopolitical intelligence collection while monetizing services for competitors.
Goals & Targeting
The strategic objective of Pitty Tiger is to acquire high‑value geopolitical and economic intelligence by infiltrating entities that manage critical infrastructure or sensitive governmental data. While the actor maintains a broad sector focus—government, defense, telecommunications, finance, energy, healthcare, among others—it exhibits a preference for organizations with rich informational assets that can be leveraged for both espionage and commoditization of stolen data to rival parties. The targeting profile indicates an opportunistic approach: initial attacks are often spear‑phishing campaigns against private firms or government contractors, followed by exploitation of known software CVEs. Once inside a network, the group seeks legitimate credentials to move laterally and establish persistence before exfiltrating classified or commercially valuable information.
Enhanced Description
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
Pitty Tiger demonstrates a predictable operational tempo characterized by periodic spear‑phishing pushes followed by rapid deployment of custom RATs that remain unknown to mainstream anti‑malware signatures. Victims tend to be medium–to‑large enterprises situated in politically sensitive regions, with campaigns tailored to exploit both social engineering weaknesses and unpatched Office document vulnerabilities. The actor often repeats similar domain naming patterns across campaigns—using short, suffix‑heavy “TEMP.” domains—which aids in automated detection but also signals a high level of adaptability. Historical activity suggests an early 2010s inception, with a focus on expanding its footprint in critical sectors while occasionally monetizing stolen credentials or data. Notable past operations include exploit chains that leveraged known CVEs such as MS17‑010 and Office document macro vulnerabilities, all coordinated through a distributed C2 infrastructure that resists takedown efforts.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
The confidence in identifying Pitty Tiger as a Chinese state‑aligned actor is moderate to high, based on corroborating reports from reputable vendors such as Airbus and FireEye. However, gaps remain regarding the exact attribution chain (e.g., definitive malware hashes linked to specific campaigns) and precise operational timelines. Additional information on their full scope of tools, supply‑chain tactics, and insider cooperation would strengthen confidence further.
No campaigns linked yet.
No observed data linked yet.
3
Techniques
48
Tools
0
Campaigns
21
IOCs
0
Observed Data
3
Tactics