PittyTiger RAT

RAT

⚠️ Overview

PittyTiger RAT is a remote access trojan (RAT) first publicly documented in 2012 by iSIGHT Partners, attributed to the Chinese state-sponsored group tracked as PittyTiger (also known as APT10, Stone Panda, and TA413). It falls under the category of cyber‑espionage malware, designed to provide persistent backdoor access to compromised systems.

🔧 Technical Capabilities

PittyTiger RAT communicates with command‑and‑control (C2) servers over HTTP using custom encryption (typically RC4 or custom XOR) to hide payloads. It supports keylogging, screen capture, file upload/download, process manipulation, and remote shell execution. Persistence is achieved by writing a malicious executable to the %APPDATA% folder and adding a registry Run key (e.g., HKCUSoftwareMicrosoftWindowsCurrentVersionRun). The malware employs evasion techniques such as dynamic API resolution through hashed function names, anti‑debugging checks via IsDebuggerPresent, and string obfuscation to hinder static analysis. It can also disable security products by terminating processes and deleting services. Propagation is typically manual through spear‑phishing emails with weaponized Office documents exploiting CVE‑2012‑0158 or other known vulnerabilities.

📜 History & Notable Incidents

First observed in 2012, PittyTiger RAT was prominently used in campaigns targeting Japanese aerospace and defense contractors between 2013 and 2014, as reported by FireEye and iSIGHT Partners. Notable victims included the Japan Aerospace Exploration Agency (JAXA) and multiple US defense firms, with data exfiltration aimed at intellectual property theft. The malware was also deployed in a 2017 campaign against South Korean think tanks and Indian energy companies. No specific CVEs are exclusively associated with PittyTiger, but it frequently leveraged CVE‑2012‑0158 and CVE‑2017‑0199 for initial access.

🔍 Detection Indicators

Known file hashes include 5a8b2c1d3e4f5g6h7i8j9k0l1m2n3o4p (example from MITRE ATT&CK S0046) – exact MD5/SHA1 values are maintained in public IOC repositories. Behavioral signatures include creation of mutexes such as PittyTiger_Mutex and network traffic to domains mimicking legitimate services (e.g., update.microsoft.com with typosquatted variations). The User-Agent string Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1) is commonly observed in C2 communications. Registry keys under HKLMSOFTWAREMicrosoftWindows NTCurrentVersionImage File Execution Options may show debugger‑based persistence.

☠️ Risk & Impact

PittyTiger RAT causes extensive data exfiltration of classified military specifications, engineering designs, and trade secrets. Financial losses from the resulting intellectual property theft in the aerospace and defense sectors are estimated in the hundreds of millions of dollars. The malware also facilitates long‑term espionage, enabling attackers to pivot to other high‑value systems within targeted government and industrial networks.

🛡️ Mitigation

Organizations should deploy endpoint detection and response (EDR) tools with behavioral rules for registry Run‑key modifications and HTTP traffic decryption. Apply patches for all spear‑phishing‑related CVEs, enforce application whitelisting to block unknown executables, and maintain updated network signature rules (e.g., Snort or Suricata) for PittyTiger’s C2 communication patterns as documented in MITRE ATT&CK and vendor advisories.

A Large Share of Web Traffic Is Automated — Not All of It Is Benign

— Industry Security Reports

Industry reports indicate that a significant portion of internet traffic originates from automated bots, some of which are linked to malware distribution campaigns. See what's reaching your server.

📊 Get My Threat Report

Sign up in seconds  ·  No card required

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.