Real-world descriptions of how a group, tool or campaign used a technique.
85 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1218.004 InstallUtil |
GroupMustang Panda | Mustang Panda has used |
| T1218.005 Mshta |
GroupMustang Panda | Mustang Panda has used mshta.exe to launch collection scripts. |
| T1219.001 IDE Tunneling |
GroupMustang Panda | Mustang Panda has utilized an established Github account to create a tunnel within the victim environment using Visual Studio Code through the `code.exe tunnel` command. |
| T1219.002 Remote Desktop Software |
GroupMustang Panda | Mustang Panda has installed TeamViewer on targeted systems. |
| T1505.003 Web Shell |
GroupMustang Panda | Mustang Panda has used China Chopper web shells to maintain access to victims’ environments. |
| T1518 Software Discovery |
GroupMustang Panda | Mustang Panda has searched the victim system for the |
| T1546.003 Windows Management Instrumentation Event Subscription |
GroupMustang Panda | Mustang Panda's custom ORat tool uses a WMI event consumer to maintain persistence. |
| T1547.001 Registry Run Keys / Startup Folder |
GroupMustang Panda | Mustang Panda has created the registry key |
| T1553.002 Code Signing |
GroupMustang Panda | Mustang Panda has used valid legitimate digital signatures and certificates to evade detection. |
| T1557 Adversary-in-the-Middle |
GroupMustang Panda | Mustang Panda leveraged a captive portal hijack that redirected the victim to a webpage that prompted the victim to download a malicious payload. |
| T1560.001 Archive via Utility |
GroupMustang Panda | Mustang Panda has used RAR to create password-protected archives of collected documents prior to exfiltration. Mustang Panda has used WinRAR “Rar.exe” to archive stolen files before exfiltration. Mustang Panda has also used TONESHELL and post-exploitation tools such as RemCom and Impacket to execute WinRAR `rar.exe` to archive files for exfiltration. |
| T1560.003 Archive via Custom Method |
GroupMustang Panda | Mustang Panda has encrypted documents with RC4 prior to exfiltration. |
| T1564.001 Hidden Files and Directories |
GroupMustang Panda | Mustang Panda's PlugX variant has created a hidden folder on USB drives named |
| T1566.001 Spearphishing Attachment |
GroupMustang Panda | Mustang Panda has used spearphishing attachments to deliver initial access payloads. Mustang Panda has also delivered archive files such as RAR and ZIP files containing legitimate EXEs and malicious DLLs. 2025_IBM_PUBLOAD_TONESHELL_HIUPAN_CLAIMLOADER_MUSTANG PANDACSIRT CTI MUSTANG PANDA PUBLOAD TONESHELL JAN 2024Cisco Talos MUSTANG PANDA PLUGX PUBLOAD MAY 2022Google TAG Ukraine Threat Landscape March 2022IBM MUSTANG PANDA PUBLOAD CLAIMLOADER JUNE 2025Lab52 MUSTANG PANDA PUBLOAD MAY 2023Proofpoint TA416 November 2020Recorded Future REDDELTA July 2020Trend Micro MUSTANG PANDA PUBLOAD HIUPAN SEPTEMBER 2024 |
| T1566.002 Spearphishing Link |
GroupMustang Panda | Mustang Panda has delivered malicious links to their intended targets. Mustang Panda has distributed spear-phishing emails with embedded links that direct the victim to a malicious archive hosted on Google or Dropbox. |
| T1567.002 Exfiltration to Cloud Storage |
GroupMustang Panda | Mustang Panda has also exfiltrated archived files to cloud services such as Dropbox using `curl`. |
| T1572 Protocol Tunneling |
GroupMustang Panda | Mustang Panda has leveraged OpenSSH (sshd.exe) to execute commands, transfer files and spread across the environment communicating over SMB port 445. |
| T1573.001 Symmetric Cryptography |
GroupMustang Panda | Mustang Panda has encrypted C2 communications with RC4. Mustang Panda has also leveraged encryption and compression algorithms to obfuscate the traffic between the system and C2 server, methods observed included RC4, AES, XOR with 0x5a, and LZO. |
| T1574.001 DLL |
GroupMustang Panda | Mustang Panda has used a legitimately signed executable to execute a malicious payload within a DLL file. Mustang Panda has abused legitimate executables to side-load malicious DLLs. 2022 November_TrendMicro_Earth Preta_Toneshell_Pubload2025_IBM_PUBLOAD_TONESHELL_HIUPAN_CLAIMLOADER_MUSTANG PANDAAnomali MUSTANG PANDA October 2019BroadcomCSIRT CTI MUSTANG PANDA PUBLOAD TONESHELL JAN 2024Cisco Talos MUSTANG PANDA PLUGX PUBLOAD MAY 2022EclecticIQ Mustang Panda PlugXEset PlugX Korplug Mustang Panda March 2022Google Threat Intelligence Group MUSTANG PANDA PLUGX August 2025IBM MUSTANG PANDA PUBLOAD CLAIMLOADER JUNE 2025Lab52 MUSTANG PANDA PUBLOAD MAY 2023Palo Alto Unit42 STATELY TAURUS TONESHELL September 2023Proofpoint TA416 November 2020Recorded Future REDDELTA July 2020Sophos PlugX September 2022Trend Micro Mustang Panda Earth Preta Toneshell February 2025Unit42 Bookworm Nov2015ZscalerZscaler PAKLOG CorkLog SplatCloak Splatdropper April 2025 |
| T1574.005 Executable Installer File Permissions Weakness |
GroupMustang Panda | Mustang Panda has leveraged legitimate software installer executables such as Setup Factory “IRSetup.exe” to drop and execute their payload. |
| T1583.001 Domains |
GroupMustang Panda | Mustang Panda has acquired C2 domains prior to operations. CSIRT CTI MUSTANG PANDA PUBLOAD TONESHELL JAN 2024Google Threat Intelligence Group MUSTANG PANDA PLUGX August 2025Lab52 MUSTANG PANDA PUBLOAD MAY 2023McAfee Dianxun March 2021Palo Alto Networks, Unit 42Recorded Future REDDELTA July 2020Secureworks BRONZE PRESIDENT December 2019Trend Micro Mustang Panda Earth Preta Toneshell February 2025Unit42 Bookworm Nov2015 |
| T1583.006 Web Services |
GroupMustang Panda | Mustang Panda has set up Dropbox and Google Drive to host malicious downloads. |
| T1585.002 Email Accounts |
GroupMustang Panda | Mustang Panda has leveraged the legitimate email marketing service SMTP2Go for phishing campaigns. Mustang Panda has also created fake Google accounts to distribute malware via spear-phishing emails. Mustang Panda has also created accounts for spearphishing operations including the use of services such as Proton Mail. |
| T1586.002 Email Accounts |
GroupMustang Panda | Mustang Panda has compromised legitimate email accounts to use in their spear-phishing operations. |
| T1587.001 Malware |
GroupMustang Panda | Mustang Panda has developed custom malware for use in their operations. |
| T1588.002 Tool |
GroupMustang Panda | Mustang Panda has obtained and leveraged publicly-available tools for intrusion activities. |
| T1588.003 Code Signing Certificates |
GroupMustang Panda | Mustang Panda has used revoked code signing certificates for its malicious payloads. |
| T1588.004 Digital Certificates |
GroupMustang Panda | Mustang Panda has obtained SSL certificates for their C2 domains. |
| T1593 Search Open Websites/Domains |
GroupMustang Panda | Mustang Panda has used open-source research to identify information about victims to use in targeting to include creating weaponized phishing lures and attachments. |
| T1598.003 Spearphishing Link |
GroupMustang Panda | Mustang Panda has delivered web bugs to profile their intended targets. |
| T1608 Stage Capabilities |
GroupMustang Panda | Mustang Panda has used servers under their control to validate tracking pixels sent to phishing victims. |
| T1608.001 Upload Malware |
GroupMustang Panda | Mustang Panda has hosted malicious payloads on DropBox including PlugX. |
| T1622 Debugger Evasion |
GroupMustang Panda | Mustang Panda has embedded debug strings with messages to distract analysts. Mustang Panda has also made calls to Windows API `CheckRemoteDebuggerPresent` and exits if it detects a debugger. |
| T1654 Log Enumeration |
GroupMustang Panda | Mustang Panda has used Wevtutil to gather Windows Security Event Logs. |
| T1678 Delay Execution |
GroupMustang Panda | Mustang Panda has delayed the execution of payloads leveraging ping echo requests `cmd /c ping 8.8.8.8 -n 70&&"%temp%\<legitimate executable>"`. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.