FlagThis
← Threat Actors
/
China
/
Putter Panda
DOSSIER // PUTTER-PANDA
Putter Panda
ACTIVE CAMPAIGN TRACKED
▲ High Threat
China
Primary Aliases:
APT2
4HCrew
G0024
Group 36
🔍 Adversary Rosetta Stone (9) ▾
📋 Copy All
Sponsor / State Affiliation
People's Liberation Army (PLA)
Primary Motivation
Strategic espionage and theft of high-value intellectual property related to defense, aerospace, and maritime technologies.
Active Timeline
Unknown – Present
Confidence Rating
90% (Grounded)
Maritime Strategic Espionage, Edge Infrastructure Exploitation
📥 Export ATT&CK Layer (.json)
🔔 RSS Feed
🏛️ CISA Advisories ↗
📋 Copy Dossier Briefing
⚔️ Weaponized CVE Matrix
(0)
No specific weaponized CVEs currently mapped in the public baseline.
🎯 Target Sectors & Focus
Aerospace
Defense
Maritime
Government
Telecommunications
Research Institutions
🛡️ MITRE ATT&CK® Attack Lifecycle
(7 TTPs)
📥 Download Navigator JSON
All Stages
7
Initial Access
2
Execution
1
Persistence & Privilege Escalation
1
Credential Access & Discovery
1
Lateral Movement & Collection
1
Command & Control
1
Initial Access
2
T1566
Spear-phishing with malicious attachments
↗
T1566
Exploitation of edge devices (VPNs, Firewalls)
↗
Execution
1
T1059
Living-off-the-land (LotL)
↗
Persistence & Privilege Escalation
1
T1547
DLL side-loading
↗
Credential Access & Discovery
1
T1003
Credential harvesting
↗
Lateral Movement & Collection
1
T1021
Lateral movement via RDP and SMB
↗
Command & Control
1
T1071
Custom backdoor deployment
↗
📰 Verified Campaigns & Intelligence Archive
🔔 Subscribe to Alerts
[DEEP DIVE]
APT28 Deploys HOOKEDGE Backdoor via webhook.site in Diplomatic Espionage Campaign
Attacks and Vulnerabilities
2026-08-29
[DEEP DIVE]
Russian APT28 Campaign Leveraging HOOKEDGE and webhook.site for European Espionage
Attacks and Vulnerabilities
2026-08-28
[DEEP DIVE]
APT28 and LameHug: AI-Driven Dynamic Command Generation
Attacks and Vulnerabilities
2026-07-03
[DEEP DIVE]
GREYVIBE Leverages ChatGPT and Google Gemini for AI-Augmented Operations against Ukraine
Attacks and Vulnerabilities
2026-07-05
[DEEP DIVE]
APT28 Exploitation of Edge Device Vulnerabilities and EOL Hardware
Attacks and Vulnerabilities
2026-06-19
[DEEP DIVE]
Strategic Pre-positioning: APT29’s Pivot Toward Critical Energy Infrastructure
Strategies and Tactics
2026-05-28
Adversary Rosetta Stone // Putter Panda
×
🔍 Mandiant / Google Threat Intel
APT2
📋
🏛️ Government / CISA / Law Enforcement
PLA Unit 61486
📋
🛡️ Other Industry Tracking Codes
4HCrew
📋
G0024
📋
Group 36
📋
MSUpdater
📋
SearchFire
📋
SULPHUR
📋
TG-6952
📋
Copied to clipboard
SHARE INTELLIGENCE WIRE
×
Story Title
X / Twitter
Bluesky
LinkedIn
Copy Link
LINK COPIED TO CLIPBOARD