PittyTiger
PittyTiger is a threat group believed to operate out of China that uses multiple different types of malware to maintain command and control.
PittyTiger is a Chinese threat group known for cyber espionage using RATs and credential dumping tools.
PittyTiger is a threat group believed to operate from China, utilizing various malware types to maintain command and control. The group primarily engages in cyber espionage, though specific targeting patterns are not defined in the provided data. Their core TTPs include using RATs like gh0st RAT, PoisonIvy, and Lurid, combined with credential theft tools such as Mimikatz and gsecdump. Defenders should focus on detecting abuse of valid accounts and monitoring for credential dumping activities associated with Mimikatz and gsecdump.
PittyTiger is a threat group believed to operate out of China that uses multiple different types of malware to maintain command and control.
Monitoring for acquired tools and detecting unusual network activity can help counter the T1588.002 technique.
To counter the Valid Accounts (T1078) technique, monitoring account activity and detecting anomalous authentication patterns is necessary.
The PittyTiger group uses remote access trojans (RATs) such as gh0st RAT, PoisonIvy, and Lurid to maintain command and control.
The group uses Mimikatz and gsecdump tools for credential dumping activities to steal credentials.
Every claim on this page is drawn from the cited source (MISP Galaxy, MITRE ATT&CK, ransomware.live) — no attribution is invented.