Putter Panda (PLA Unit 61486) intrusions against satellite and aerospace industries (disclosed 2014)
What happened
CrowdStrike published its Putter Panda report on 9 June 2014, attributing a long-running espionage campaign to Unit 61486 of the 12th Bureau of the People's Liberation Army's 3rd General Staff Department, headquartered in Shanghai's Zhabei District. The company had tracked the group since 2012 and dated its activity to at least 2007. CrowdStrike states that the group heavily targeted the US defence and European satellite and aerospace industries, and that its objective was intellectual property from the space, satellite and remote-sensing technology sectors, from aerospace companies and from telecommunications firms in Japan and Europe. Delivery was by targeted email carrying weaponised documents that exploited existing vulnerabilities in Adobe Reader and Microsoft Office with off-the-shelf exploits, deploying custom remote access tools. The attribution turns on domain registrations and on personal photographs tied to Chen Ping, who used the handles cpyy, cpiyy and cpyy.chen, and it reports overlaps in tooling and infrastructure with Unit 61398, the group known as Comment Crew. No victim organisation is named.
This is a sector-level record, not an incident-level one. No victim is named, no intrusion is dated, and no document set is identified: what is public is a vendor's characterisation of a decade of activity plus an attribution to a named unit and a named individual. It is included because the targeting statement is unusually specific about the space sector, and it carries one derived edge on that basis. The single technique SPARTA's bibliography cites, REC-0009 (Gather Mission Information), is rejected in favour of REC-0001 for reasons given in the markdown narrative. SCOPE UNDETERMINED, recorded 2026-08-23. Whether this record belongs in this corpus has not been established. A record is admitted here when a space system, meaning a spacecraft, a mission ground segment, a tracking or command path or a launch system, is in the attack path; the victim being a space-sector organisation is expressly not the test. What the sources establish is a sector-level account and an attribution. CrowdStrike dates the group's activity to at least 2007, describes delivery by targeted email carrying weaponised documents, and states of the victims: "The mission of 12th Bureau unit 61486 lines up quite nicely with the observed victims, specifically the satellite technology companies associated with this activity." So the victims are characterised as a class, and satellite technology companies are space-sector organisations, which is expressly not the test. What no cited source establishes is what was reached inside one. No victim organisation is named, no individual intrusion is dated, and no document set is identified, so the record carries a single derived edge at moderate confidence. One distinction in the primary source is easy to lose and is recorded here: the list of sectors of interest is introduced as "Observations from social engineering topics used by PUTTER PANDA", which describes the lures rather than the confirmed victims, while the sentence quoted above describes the victims. A source naming a victim organisation together with a compromised system on that victim's side that is a spacecraft, a ground control segment, a telemetry or command path, a mission operations workstation or launch ground support equipment would settle it one way; a source characterising the reached systems as the manufacturers' corporate estates would settle it the other. Sector-level targeting language will not settle it however specific it becomes about the sector. The record stays published while the question is open, under decisions entry 189.
Attack vector
Targeted email carrying weaponised documents exploiting existing Adobe Reader and Microsoft Office vulnerabilities with off-the-shelf exploits, deploying custom remote access tools.
Operational impact
None reported. No source describes an effect on any mission, spacecraft or ground system.
Data compromised
Not itemised. Threatpost describes exfiltration of data from unnamed companies in the space and defence industries; CrowdStrike states the objective as intellectual property from named sectors.
Affected segments
supply_chain
Disclosed
2014-06-09
SPARTA techniques evidenced
Each row is a technique this record evidences, with the reasoning and the source that attests to it.
What relationship, confidence, and evidence mean on the rows below
- Relationship
What kind of link this is between the technique and the target.
Mitigates: the target actively prevents, detects, or recovers from the technique.
Addresses: the target governs the technique or is relevant to it, without interdicting it. Most governance and policy obligations sit here.
Triggers obligation: the technique occurring is what triggers the duty the target imposes.
Relates to: related to the technique, but the target neither interdicts nor governs it. Used sparingly.
- Confidence
How strongly the source supports this mapping, not how severe the technique is.
High: the source supports the mapping squarely.
Moderate: supported, with a qualification such as a cross-tactic reading that stays operationally sound.
Low: the source reaches the technique only in part.
- Evidence
How close to the source text the mapping was made.
Direct: a verbatim excerpt of the cited source was read against the technique, and the rationale argues from that excerpt.
Derived: the mapping follows from the source's scope or structure, with no on-point excerpt addressing the technique.
Inferred: reached by composition through another framework, or by domain reasoning the source does not support on its face.
CrowdStrike states the group's objective as acquiring intellectual property from the space, satellite and remote-sensing technology sectors and from aerospace companies, and Threatpost reports data exfiltrated from unnamed companies in the space and defence industries. REC-0001 is the technique whose objective is that body of material, the design picture of spacecraft and their supporting ecosystem held by manufacturers and integrators. The edge is derived and moderate because neither source names a victim, a programme or a document, so the content of what was collected is characterised at sector level only.
Considered and not mapped
These techniques were considered for this record because a source, a related record or SPARTA's own catalogue pointed at them. Each was read against what the sources say and not mapped. The reason is given in full.
SPARTA's own citation, and the closer-looking one at first glance. Rejected because REC-0009's subject is a CONOPS-level portrait, duty cycles, mode logic, pointing and thermal constraints, campaign and calibration schedules, assembled to choose a moment to act. Neither source describes anything of the kind. What both describe is intellectual property theft from manufacturers, which is REC-0001's object. Preferring the specific over the general is the same rule the mapping conventions apply to regulation sub-paragraphs.
Sources
The published accounts this record rests on. The tier is SafeMode Space's own assessment of the source, and the reason for it is given beside it. What the tiers mean and how they are assigned: the source tiers.
A source is listed when a mapped technique rests on it, or when it disputes the account. One the curators read but neither cited nor recorded as disputing the record is not listed, so an absence here means neither is true rather than that nobody looked.
- Hat-tribution to PLA Unit 61486Vendor threat intelligence
Tier 2: First-party publication of the vendor's own intelligence report, with the unit designation, the location and the named individual set out and the attribution method described.
Tier 3: Security trade outlet with a named reporter, summarising the vendor report. Independent of the vendor on framing, dependent on it for every fact.
Every source SafeMode Space reproduces, and on what terms: sources and attribution.