Tom Fakterman. (2024, September 6). Chinese APT Abuses VSCode to Target Government in Asia. Retrieved March 24, 2025.
None recorded.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1016 System Network Configuration Discovery |
GroupMustang Panda | Mustang Panda has used |
| T1018 Remote System Discovery |
GroupMustang Panda | Mustang Panda has queried Active Directory for computers using AdFind. Mustang Panda has also utilized SharpNBTScan to scan the victim environment. |
| T1027.001 Binary Padding |
MalwareTONESHELL | TONESHELL has used randomized padding to obfuscate payloads. |
| T1053.005 Scheduled Task |
GroupMustang Panda | Mustang Panda has created a scheduled task to execute additional malicious software, as well as maintain persistence. Mustang Panda has also created a scheduled task that creates a reverse shell. |
| T1059.001 PowerShell |
GroupMustang Panda | Mustang Panda has used malicious PowerShell scripts to enable execution. |
| T1105 Ingress Tool Transfer |
GroupMustang Panda | Mustang Panda has downloaded additional executables following the initial infection stage. Mustang Panda has also leveraged Visual Studio Code `code.exe` and Dev Tunnels using `DevTunnel.exe` to propagate additional tools and payloads. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareTONESHELL | TONESHELL has decoded its payload prior to execution. |
| T1176.002 IDE Extensions |
GroupMustang Panda | Mustang Panda has leveraged Visual Studio Code’s (VSCode) embedded reverse shell feature using the command `code.exe tunnel` to execute code and deliver additional payloads. |
| T1219.001 IDE Tunneling |
GroupMustang Panda | Mustang Panda has utilized an established Github account to create a tunnel within the victim environment using Visual Studio Code through the `code.exe tunnel` command. |
| T1560.001 Archive via Utility |
GroupMustang Panda | Mustang Panda has used RAR to create password-protected archives of collected documents prior to exfiltration. Mustang Panda has used WinRAR “Rar.exe” to archive stolen files before exfiltration. Mustang Panda has also used TONESHELL and post-exploitation tools such as RemCom and Impacket to execute WinRAR `rar.exe` to archive files for exfiltration. |
| T1560.001 Archive via Utility |
MalwareTONESHELL | TONESHELL used WinRAR rar.exe to archive files for exfiltration. TONESHELL has also utilized a unique 13-character password consisting of upper lower case and digits to protect RAR archives. |
| T1567.002 Exfiltration to Cloud Storage |
GroupMustang Panda | Mustang Panda has also exfiltrated archived files to cloud services such as Dropbox using `curl`. |
| T1572 Protocol Tunneling |
GroupMustang Panda | Mustang Panda has leveraged OpenSSH (sshd.exe) to execute commands, transfer files and spread across the environment communicating over SMB port 445. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.