Putter Panda
G00242 reportsaliases · Putter Panda · APT2 · MSUpdater
2
Reports
11
Techniques
7
Tactics
3
Countries
55%
Hunt coverage
3
Aliases
Analyst assessment — key judgments
- Signature techniques: T1588.006 (Vulnerabilities), T1059.001 (PowerShell), T1589.001 (Credentials).
- Primary targeting: RU, US, BR.
- Resurgent after a quiet period: 1 report(s) in last 30d vs 0 prior (+100%).
- Recent movement: 6 new technique(s), 17 new infrastructure indicator(s) in the last 30 days.
- Hunt coverage 55% of 11 observed techniques (5 gap(s)).
- Assessment confidence: medium (60).
Activity & trend
ResurgentLast 30d: 1 vs 0 prior (+100%)· first reported 2026-07-03 · last 2026-09-16
1
7d
1
30d
2
90d
2
All
0.2
Rpts/wk
Reporting timeline · 12 months
Movement — last 30 days
New techniques
T1590.005T1087.001T1136.001T1583.006T1584.006T1078.002Targeting gained
RUUSNew infrastructure
1dcafb7f8448683281106b06dd22409a1f3034b706c78b35d8e34044e68c693a3ecd1cd627d0340c92901a478a7caad8631fb131a56caf4ca0f287ed73e876ab4aa9fb1bf9223dfcdac920759bc7a3c7https://www.kaspersky.com/enterprise-sechttps://www.kaspersky.com/enterprise-sechttps://tip.kaspersky.com/landscape/hunthttps://tip.kaspersky.com/landscape/hunthttps://tip.kaspersky.com/landscape/hunthttps://tip.kaspersky.com/landscape/hunthttps://tip.kaspersky.com/landscape/huntVulnerabilities in this actor's reporting · 2
- CVE-2019-0708KEV1 rpt
- CVE-2020-0688KEV1 rpt
Overview
Analyst triage
Intelligence summary
Putter Panda is a Chinese threat group that has been attributed to Unit 61486 of the 12th Bureau of the PLA’s 3rd General Staff Department (GSD). (Citation: CrowdStrike Putter Panda)
Top co-occurring indicators
Aliases & naming
Targeting · countries
Targeting · named victims
ATT&CK technique matrix
Coverage vs hunt library:
—
Hunt-coverage gaps — prioritized
Top techniques by observation
- T1588.006 · Vulnerabilitiesconf 602
- T1059.001 · PowerShellconf 602
- T1589.001 · Credentialsconf 602
- T1053.005 · Scheduled Taskconf 601
- T1204.002 · Malicious Fileconf 601
- T1590.005 · IP Addressesconf 601evidence: NightEagle targets Russian companies
- T1087.001 · Local Accountconf 601evidence: NightEagle targets Russian companies
- T1136.001 · Local Accountconf 601evidence: NightEagle targets Russian companies
- T1583.006 · Web Servicesconf 601evidence: NightEagle targets Russian companies
- T1584.006 · Web Servicesconf 601evidence: NightEagle targets Russian companies
- T1078.002 · Domain Accountsconf 601evidence: NightEagle targets Russian companies
Threat catalogue · engineering roadmap
Flagged detection-engineering queue
Uncovered techniques you flagged for hunt / detection build-out, aggregated across every actor you visit. Stored locally in your browser.
Infrastructure
IOC type mix
Tooling / malware families
Relationships
Activity
30-day mention timeline
Recent reporting
| Title | Source | Severity | Collected |
|---|