Introduction
PittyTiger is a threat group believed to operate out of China that uses multiple different types of malware to maintain command and control. Bizeul 2014 Villeneuve 2014
Activities and Tactics
Country of Origin: 🇨🇳 China
Notable Campaigns
Information pending cataloguing.
Tactics, Techniques, and Procedures (TTPs)
ATT&CK technique IDs (denormalized)
Notable Indicators of Compromise (IOCs)
No curated IOCs are currently published for this actor. This section will be updated when stable, attributable indicators are available.
Malware and Tools
- PittyTiger:
- Paladin RAT:
MITRE ATT&CK Software
- gh0st RAT (S0032) — malware
- Lurid (S0010) — malware
- gsecdump (S0008) — tool
- PoisonIvy (S0012) — malware
- Mimikatz (S0002) — tool
Attribution and Evidence
Country of Origin: China Additional attribution information pending cataloguing.
References
[1] mitre-attack [3] Bizeul 2014 Bizeul, D., Fontarensky, I., Mouchoux, R., Perigaud, F., Pernet, C. (2014, July 11). Eye of the Tiger. Retrieved September 29, 2015. [4] Villeneuve 2014 Villeneuve, N., Homan, J. (2014, July 31). Spy of the Tiger. Retrieved September 29, 2015.