Loading the current evidence view. Navigation and account controls remain available.
Threat actors
Loading the current evidence view. Navigation and account controls remain available.
2
techniques
5
software
1,463
corpus matches
profile
PittyTiger is a threat group believed to operate out of China that uses multiple different types of malware to maintain command and control.
techniques
2 attributed · most-instrumented first
software
5 malware & tools attributed
Mimikatz
S0002
gsecdump
S0008
Lurid
S0010
PoisonIvy
S0012
gh0st RAT
S0032
read this carefully
1,463 corpus matches is not attribution
That count is indicators which exhibit techniques PittyTiger is known to use. Many unrelated operators use the same techniques. Treat it as a shared-technique signal for hunting, never as first-party attribution to this group.
indicators exhibiting these techniques
Top by severity: each resolves to its own verdict.
showing 30 of 1,463