APT24 — APT Profile
The Pitty Tiger group has been active since at least 2011. They have been seen using HeartBleed vulnerability in order to directly get valid credentialsAlso tracked as
PittyTiger, G0011, PITTY PANDA, Temp.Pittytiger
Tools & malware
- gh0st RAT Remote Access Trojan
- gsecdump Credential Harvesting
- Lurid Backdoor
- Mimikatz Credential Harvesting
- PoisonIvy Remote Access Trojan
- win.badaudio Backdoor
Vendor research
- Eye of the Tiger Bizeul, D., Fontarensky, I., Mouchoux, R., Perigaud, F., Pernet, C
- Spy of the Tiger Villeneuve, N., Homan, J
- Spy of the Tiger Villeneuve
- Eye of the Tiger Bizeul