APT24, also known as Pitty Panda and G0011, is a China-nexus espionage threat actor active since at least 2011 and commonly assessed as aligned with People’s Republic of China intelligence objectives. The group has been associated with long-running cyberespionage operations that evolved from watering-hole and web-compromise activity into broader multi-vector intrusion campaigns, including targeted phishing, social engineering, and supply-chain compromise. APT24 has notably targeted organizations in Taiwan and has also been reported targeting entities in the United States. Reported operations include compromise of public-facing websites to inject malicious JavaScript that presents fake software-update lures to Windows users, as well as compromise of a regional digital marketing firm to facilitate downstream supply-chain attacks across a large set of customer-linked domains. The actor has also conducted highly targeted phishing campaigns using themed lures and has abused legitimate cloud storage services to distribute encrypted archives containing malware. A malware family prominently associated with APT24 is BADAUDIO, a downloader used in a multi-year espionage campaign. BADAUDIO performs host reconnaissance, gathers basic system-identifying information, encrypts collected data, communicates over HTTP, and can retrieve and execute follow-on payloads. Public analysis has also highlighted APT24’s use of practical defense-evasion measures such as string obfuscation, encrypted communications, and blending malicious traffic with legitimate cloud-hosted infrastructure. Broader reporting characterizes the group’s tradecraft as adaptive and persistent, combining web compromises, spearphishing, supply-chain access, and stealth-oriented delivery techniques in support of intelligence collection.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
13 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
4 malware families attributed to this actor across reporting.
9 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
China-linked intrusion set associated with the BadAudio downloader. The group is described as using custom tooling, including the BADAUDIO first-stage downloader, for reconnaissance, encrypted host-data collection, and HTTP-based C2 communications.
China-nexus espionage actor using BADAUDIO for persistent access; campaign noted as hitting Taiwan and large numbers of domains.
APT24 is referenced as shifting from watering-hole activity toward multi-vector attacks.
PRC-nexus cyber-espionage actor with a Taiwan focus; uses an obfuscated first-stage downloader and has shifted from broad web compromises to multi-vector operations including supply-chain compromise of a marketing firm and targeted phishing.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.