Real-world descriptions of how a group, tool or campaign used a technique.
85 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1001.003 Protocol or Service Impersonation |
GroupMustang Panda | Mustang Panda has utilized TLS record headers in network packets to impersonate various versions of TLS protocols to blend in with legitimate network traffic. Mustang Panda has used FakeTLS to communicate with its C2 servers. |
| T1003 OS Credential Dumping |
GroupMustang Panda | Mustang Panda utilized “Hdump” to dump credentials from memory. |
| T1003.001 LSASS Memory |
GroupMustang Panda | Mustang Panda has harvested credentials from memory of lssas.exe with Mimikatz. |
| T1003.003 NTDS |
GroupMustang Panda | Mustang Panda has used vssadmin to create a volume shadow copy and retrieve the NTDS.dit file. Mustang Panda has also used |
| T1003.006 DCSync |
GroupMustang Panda | Mustang Panda has leveraged Mimikatz DCSync feature to obtain user credentials. |
| T1016 System Network Configuration Discovery |
GroupMustang Panda | Mustang Panda has used |
| T1018 Remote System Discovery |
GroupMustang Panda | Mustang Panda has queried Active Directory for computers using AdFind. Mustang Panda has also utilized SharpNBTScan to scan the victim environment. |
| T1027 Obfuscated Files or Information |
GroupMustang Panda | Mustang Panda has delivered initial payloads hidden using archives and encoding measures. Mustang Panda has also utilized opaque predicates in payloads to hinder analysis. 2022 November_TrendMicro_Earth Preta_Toneshell_PubloadAnomali MUSTANG PANDA October 2019Cisco Talos MUSTANG PANDA PLUGX PUBLOAD MAY 2022Crowdstrike MUSTANG PANDA June 2018Eset PlugX Korplug Mustang Panda March 2022Proofpoint TA416 Europe March 2022Proofpoint TA416 November 2020Recorded Future REDDELTA July 2020Secureworks BRONZE PRESIDENT December 2019Sophos PlugX September 2022Unit42 Bookworm Nov2015ZscalerZscaler PAKLOG CorkLog SplatCloak Splatdropper April 2025 |
| T1027.007 Dynamic API Resolution |
GroupMustang Panda | Mustang Panda has leveraged obfuscated Windows API function calls that were concealed as unique names, or hashes of the Windows API. |
| T1027.012 LNK Icon Smuggling |
GroupMustang Panda | Mustang Panda has utilized LNK files to hide malicious scripts for execution. Mustang Panda has also leveraged LNK files that were programmed to display a PDF icon to entice the victim to click on the file to execute an office.exe binary. |
| T1027.016 Junk Code Insertion |
GroupMustang Panda | Mustang Panda has used junk code within their DLL files to hinder analysis. |
| T1036.005 Match Legitimate Resource Name or Location |
GroupMustang Panda | Mustang Panda has used names like `adobeupdate.dat` and `PotPlayerDB.dat` to disguise PlugX, and a file named `OneDrive.exe` to load a Cobalt Strike payload. Mustang Panda has also masqueraded legitimate browser plugin updates to include AdobePlugins.exe. |
| T1036.007 Double File Extension |
GroupMustang Panda | Mustang Panda has used an additional filename extension to hide the true file type. |
| T1036.008 Masquerade File Type |
GroupMustang Panda | Mustang Panda has masqueraded malicious executables as legitimate files that download PlugX malware. |
| T1041 Exfiltration Over C2 Channel |
GroupMustang Panda | Mustang Panda has exfiltrated stolen data and files to its C2 server. |
| T1046 Network Service Discovery |
GroupMustang Panda | Mustang Panda has leveraged NBTscan to scan IP networks. |
| T1047 Windows Management Instrumentation |
GroupMustang Panda | Mustang Panda has executed PowerShell scripts via WMI. |
| T1048.003 Exfiltration Over Unencrypted Non-C2 Protocol |
GroupMustang Panda | Mustang Panda has used FTP to exfiltrate archive files. |
| T1049 System Network Connections Discovery |
GroupMustang Panda | Mustang Panda has used |
| T1052.001 Exfiltration over USB |
GroupMustang Panda | Mustang Panda has used a customized PlugX variant which could exfiltrate documents from air-gapped networks. |
| T1053.005 Scheduled Task |
GroupMustang Panda | Mustang Panda has created a scheduled task to execute additional malicious software, as well as maintain persistence. Mustang Panda has also created a scheduled task that creates a reverse shell. |
| T1057 Process Discovery |
GroupMustang Panda | Mustang Panda has used |
| T1059 Command and Scripting Interpreter |
GroupMustang Panda | Mustang Panda has utilized meterpreter shellcode. |
| T1059.001 PowerShell |
GroupMustang Panda | Mustang Panda has used malicious PowerShell scripts to enable execution. |
| T1059.003 Windows Command Shell |
GroupMustang Panda | Mustang Panda has executed HTA files via cmd.exe, and used batch scripts for collection. Mustang Panda has also utilized cmd.exe to execute commands on an infected host such as `cmd.exe /c ping.exe 8.8.8.8 -n 70&&"%temp%\FontEDL.exe"`. |
| T1059.005 Visual Basic |
GroupMustang Panda | Mustang Panda has embedded VBScript components in LNK files to download additional files and automate collection. Mustang Panda has also used VBA macros in maldocs to execute malicious DLLs. Mustang Panda also utilized a VBS Script “autorun.vbs” that created persistence through saving the VBS Script in the startup directory which would cause it to run each time the machine was turned on. |
| T1059.007 JavaScript |
GroupMustang Panda | Mustang Panda has executed a JavaScript payload utilizing wscript.exe on the endpoint. |
| T1069.002 Domain Groups |
GroupMustang Panda | Mustang Panda has leveraged AdFind to enumerate domain groups. |
| T1070 Indicator Removal |
GroupMustang Panda | Mustang Panda has deleted registry keys that store data and maintained persistence. |
| T1070.004 File Deletion |
GroupMustang Panda | Mustang Panda will delete their tools and files, and kill processes after their objectives are reached. |
| T1070.006 Timestomp |
GroupMustang Panda | Mustang Panda has modified file timestamps from the export address table (EAT) in malware to make it difficult to identify creation times. |
| T1071.001 Web Protocols |
GroupMustang Panda | Mustang Panda has communicated with its C2 via HTTP POST requests. |
| T1072 Software Deployment Tools |
GroupMustang Panda | Mustang Panda has leveraged legitimate software tools such as AntiVirus Agents, Security Services, and App Development tools to execute scripts and to side-load dlls. |
| T1074.001 Local Data Staging |
GroupMustang Panda | Mustang Panda has stored collected credential files in |
| T1082 System Information Discovery |
GroupMustang Panda | Mustang Panda has gathered system information using |
| T1083 File and Directory Discovery |
GroupMustang Panda | Mustang Panda has searched the entire target system for DOC, DOCX, PPT, PPTX, XLS, XLSX, and PDF files. |
| T1087.002 Domain Account |
GroupMustang Panda | Mustang Panda has utilized AdFind to identify domain users. |
| T1091 Replication Through Removable Media |
GroupMustang Panda | Mustang Panda has used a customized PlugX variant which could spread through USB connections. |
| T1095 Non-Application Layer Protocol |
GroupMustang Panda | Mustang Panda has utilized TCP-based reverse shells using cmd.exe. |
| T1102 Web Service |
GroupMustang Panda | Mustang Panda has used DropBox URLs to deliver variants of PlugX. Mustang Panda has also used Google Drive to host malicious downloads. |
| T1105 Ingress Tool Transfer |
GroupMustang Panda | Mustang Panda has downloaded additional executables following the initial infection stage. Mustang Panda has also leveraged Visual Studio Code `code.exe` and Dev Tunnels using `DevTunnel.exe` to propagate additional tools and payloads. |
| T1106 Native API |
GroupMustang Panda | Mustang Panda has used various Windows API calls during execution and defense evasion. 2022 November_TrendMicro_Earth Preta_Toneshell_Pubload2025_IBM_PUBLOAD_TONESHELL_HIUPAN_CLAIMLOADER_MUSTANG PANDABroadcomEset PlugX Korplug Mustang Panda March 2022Google Threat Intelligence Group MUSTANG PANDA PLUGX August 2025IBM MUSTANG PANDA PUBLOAD CLAIMLOADER JUNE 2025Lab52 MUSTANG PANDA PUBLOAD MAY 2023Palo Alto Networks, Unit 42Sophos Mustang Panda PLUGXTrend Micro Mustang Panda Earth Preta Toneshell February 2025ZscalerZscaler PAKLOG CorkLog SplatCloak Splatdropper April 2025 |
| T1119 Automated Collection |
GroupMustang Panda | Mustang Panda used custom batch scripts to collect files automatically from a targeted system. |
| T1129 Shared Modules |
GroupMustang Panda | Mustang Panda has leveraged `LoadLibrary` to load DLLs. |
| T1140 Deobfuscate/Decode Files or Information |
GroupMustang Panda | Mustang Panda has the ability to decrypt its payload prior to execution. Mustang Panda has also utilized RC4 encryption for malicious payloads. |
| T1176.002 IDE Extensions |
GroupMustang Panda | Mustang Panda has leveraged Visual Studio Code’s (VSCode) embedded reverse shell feature using the command `code.exe tunnel` to execute code and deliver additional payloads. |
| T1203 Exploitation for Client Execution |
GroupMustang Panda | Mustang Panda has exploited CVE-2017-0199 in Microsoft Word to execute code. |
| T1204.001 Malicious Link |
GroupMustang Panda | Mustang Panda has sent malicious links including links directing victims to a Google Drive folder. Mustang Panda has also utilized webpages with Javascript code that downloads malicious payloads to the victim device. 2022 November_TrendMicro_Earth Preta_Toneshell_Pubload2025_IBM_PUBLOAD_TONESHELL_HIUPAN_CLAIMLOADER_MUSTANG PANDACrowdstrike MUSTANG PANDA June 2018Google Threat Intelligence Group MUSTANG PANDA PLUGX August 2025IBM MUSTANG PANDA PUBLOAD CLAIMLOADER JUNE 2025McAfee Dianxun March 2021Proofpoint TA416 Europe March 2022 |
| T1204.002 Malicious File |
GroupMustang Panda | Mustang Panda has sent malicious files requiring direct victim interaction to execute. Mustang Panda has also leveraged executable files that display decoy documents to the victim to provide a resemblance of legitimacy with customized themes related to the victim. 2022 November_TrendMicro_Earth Preta_Toneshell_Pubload2025_IBM_PUBLOAD_TONESHELL_HIUPAN_CLAIMLOADER_MUSTANG PANDAAnomali MUSTANG PANDA October 2019Avira Mustang Panda January 2020CSIRT CTI MUSTANG PANDA PUBLOAD TONESHELL JAN 2024Cisco Talos MUSTANG PANDA PLUGX PUBLOAD MAY 2022Crowdstrike MUSTANG PANDA June 2018EclecticIQ Mustang Panda PlugXEset PlugX Korplug Mustang Panda March 2022Google TAG Ukraine Threat Landscape March 2022IBM MUSTANG PANDA PUBLOAD CLAIMLOADER JUNE 2025Lab52 MUSTANG PANDA PUBLOAD MAY 2023Palo Alto Networks, Unit 42Proofpoint TA416 Europe March 2022Recorded Future REDDELTA July 2020Sophos Mustang Panda PLUGXSophos PlugX September 2022Trend Micro MUSTANG PANDA PUBLOAD HIUPAN SEPTEMBER 2024Trend Micro Mustang Panda Earth Preta Toneshell February 2025Unit42 Bookworm Nov2015Zscaler PAKLOG CorkLog SplatCloak Splatdropper April 2025 |
| T1205 Traffic Signaling |
GroupMustang Panda | Mustang Panda has utilized a magic value in C2 communications and only executes in memory when response packets match specific values of “17 03 03” or “46 77 4d”. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.