Putter Panda
MITRE: G0024Putter Panda is a Chinese threat group that has been attributed to Unit 61486 of the 12th Bureau of the PLAâs 3rd General Staff Department (GSD).
Alternate names
APT2, MSUpdater,
Putter Panda is an advanced persistent threat (APT) that has been active since at least 2013, targeting organizations in various industries such as finance and healthcare. It is believed to be a Chinese state-sponsored group with links to the People's Liberation Army (PLA). Putter Panda uses sophisticated techniques to gain access to their targets through spear phishing emails, watering hole attacks, and exploiting vulnerabilities in software. Once inside an organization's network, they can steal sensitive information such as financial data or intellectual property for espionage purposes. The group has been known to target specific individuals within organizations, using social engineering tactics to gain their trust before launching a successful attack.
Techniques, tactics and practices:
Putter Panda uses various techniques such as spear phishing emails that contain malicious attachments or links to infected websites. They also use watering hole attacks, where they compromise a legitimate website and inject it with malware, which then spreads to the visitors of the site. The group has been known to exploit vulnerabilities in software such as Adobe Flash Player, Microsoft Office, and Java to gain access to their targets' networks. They also use social engineering tactics to gain trust from specific individuals within organizations before launching a successful attack.
