Putter Panda is a threat actor also referred to in the provided content as APT2 and MSUpdater. The content links the group to malware and droppers that establish persistence via the Windows ASEP Registry key HKCU\Software\Microsoft\Windows\CurrentVersion\Run using the value name McUpdate. The group’s droppers are described as obfuscating payloads with RC4 or with a 16-byte XOR key consisting of bytes 0xA0 through 0xAF. Malware attributed to Putter Panda is also described as attempting to terminate Sophos Anti-Virus components SAVAdminService.exe and SavService.exe, indicating defense evasion or tool impairment activity. The content additionally references reporting that compared identifying details from the online persona baobeilong to cpyy in CrowdStrike’s PUTTER PANDA report, but does not provide higher-confidence attribution details beyond that mention.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
12 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Listed as a threat actor associated with the PowerShell P/Invoke process injection API chain detection and related ATT&CK techniques.
Referenced as a threat actor associated with disabling or modifying tools.
Referenced as a threat actor associated with the defense-impairment technique of modifying Windows Filtering Platform policy to block EDR process communication.
Referenced as a threat actor associated with the technique of disabling or modifying security tools, specifically in the context of CrowdStrike agent registry key removal detection.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.