Lenart Bermejo, Sunny Lu, Ted Lee. (2024, September 9). Earth Preta Evolves its Attacks with New Malware and Strategies. Retrieved August 4, 2025.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1007 System Service Discovery |
MalwarePUBLOAD | PUBLOAD has leveraged `tasklist` to gather running services on victim host. |
| T1012 Query Registry |
MalwarePUBLOAD | PUBLOAD has queried Registry values to identify software using `reg query`. |
| T1016 System Network Configuration Discovery |
MalwarePUBLOAD | PUBLOAD has obtained information about local networks through the `ipconfig /all` command. |
| T1016.001 Internet Connection Discovery |
MalwarePUBLOAD | PUBLOAD has identified internet connectivity details through commands such as `tracert -h 5 -4 google.com` and `curl http://myip.ipip.net`. |
| T1016.002 Wi-Fi Discovery |
MalwarePUBLOAD | PUBLOAD has collected information on Wi-Fi networks from victim hosts leveraging `netsh wlan show profiles`, `netsh wlan show interface`, and `netsh wlan show`. |
| T1047 Windows Management Instrumentation |
MalwarePUBLOAD | PUBLOAD has used `wmic` to gather information from the victim device. |
| T1048.003 Exfiltration Over Unencrypted Non-C2 Protocol |
MalwarePUBLOAD | PUBLOAD has leveraged `curl` for data exfiltration over FTP by uploading RAR archives containing targeted files (.doc, .docx, .xls, .xlsx, .pdf, .ppt, .pptx) to an adversary-owned FTP site. |
| T1049 System Network Connections Discovery |
MalwarePUBLOAD | PUBLOAD has used several commands executed in sequence via `cmd` in a short interval to gather information on network connections. |
| T1057 Process Discovery |
MalwarePUBLOAD | PUBLOAD has used `tasklist` to gather running processes on victim host. PUBLOAD has also leveraged the `OpenEventA` Windows API function to check whether the same process was already running. |
| T1057 Process Discovery |
MalwareHIUPAN | HIUPAN has conducted process discovery to identify the PUBLOAD malware under the process WCBrowserWatcher.exe and will launch it from an install directory if it is not found. |
| T1059.003 Windows Command Shell |
MalwarePUBLOAD | PUBLOAD has used several commands executed in sequence via `cmd`. |
| T1071.001 Web Protocols |
MalwarePUBLOAD | PUBLOAD has communicated via `curl` over HTTP to identify device IP data. PUBLOAD has also utilized HTTP for a command-and-control protocol through HTTP POST. PUBLOAD has also leveraged HTTPS for C2. |
| T1071.002 File Transfer Protocols |
MalwarePUBLOAD | PUBLOAD has used `curl` for data exfiltration over FTP. |
| T1082 System Information Discovery |
MalwarePUBLOAD | PUBLOAD has collected and sent system information including volume serial number, computer name, and system uptime to designated C2. PUBLOAD has also used several commands executed in sequence via `cmd` in a short interval to gather system information about the infected host including `systeminfo`. PUBLOAD has decrypted shellcode that collects the computer name. |
| T1091 Replication Through Removable Media |
MalwareHIUPAN | HIUPAN has periodically checked for removable and hot-plugged drives connected to the infected machine, should one be found HIUPAN will propagate to the removeable drives by copying itself and accompanying malware components to a directory to the new drive in a hidden subdirectory `<Drive_Letter>:\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\` and hides any other existing files to ensure UsbConfig.exe is the only visible file on the device. |
| T1105 Ingress Tool Transfer |
MalwarePUBLOAD | PUBLOAD has acted as a stager that can download the next-stage payload from its C2 server. PUBLOAD has also delivered FDMTP as a secondary control tool and PTSOCKET for exfiltration to some infected systems. |
| T1112 Modify Registry |
MalwareHIUPAN | HIUPAN has modified registry keys to ensure hidden files and extensions are not visible through the modification of `HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced`. |
| T1120 Peripheral Device Discovery |
MalwareHIUPAN | HIUPAN has checked periodically for removable drives and installs itself when a drive is detected. |
| T1204.002 Malicious File |
GroupMustang Panda | Mustang Panda has sent malicious files requiring direct victim interaction to execute. Mustang Panda has also leveraged executable files that display decoy documents to the victim to provide a resemblance of legitimacy with customized themes related to the victim. 2022 November_TrendMicro_Earth Preta_Toneshell_Pubload2025_IBM_PUBLOAD_TONESHELL_HIUPAN_CLAIMLOADER_MUSTANG PANDAAnomali MUSTANG PANDA October 2019Avira Mustang Panda January 2020CSIRT CTI MUSTANG PANDA PUBLOAD TONESHELL JAN 2024Cisco Talos MUSTANG PANDA PLUGX PUBLOAD MAY 2022Crowdstrike MUSTANG PANDA June 2018EclecticIQ Mustang Panda PlugXEset PlugX Korplug Mustang Panda March 2022Google TAG Ukraine Threat Landscape March 2022IBM MUSTANG PANDA PUBLOAD CLAIMLOADER JUNE 2025Lab52 MUSTANG PANDA PUBLOAD MAY 2023Palo Alto Networks, Unit 42Proofpoint TA416 Europe March 2022Recorded Future REDDELTA July 2020Sophos Mustang Panda PLUGXSophos PlugX September 2022Trend Micro MUSTANG PANDA PUBLOAD HIUPAN SEPTEMBER 2024Trend Micro Mustang Panda Earth Preta Toneshell February 2025Unit42 Bookworm Nov2015Zscaler PAKLOG CorkLog SplatCloak Splatdropper April 2025 |
| T1204.002 Malicious File |
MalwareHIUPAN | HIUPAN has lured victims into executing malicious files from USBs including the use of files such as USBconfig.exe. |
| T1518 Software Discovery |
MalwarePUBLOAD | PUBLOAD has used several commands executed in sequence via `cmd` in a short interval to gather software versions including querying Registry keys. |
| T1518.001 Security Software Discovery |
MalwarePUBLOAD | PUBLOAD has identified AV products on an infected host using the following command: `WMIC /Node:localhost /Namespace:\\root\SecurityCenter2 Path AntiVirusProduct Get displayName /Format:List`. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwarePUBLOAD | PUBLOAD has added Registry Run keys to achieve persistence using `HKCU\Software\Microsoft\Windows\CurrentVersion\Run`. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareHIUPAN | HIUPAN has added Registry Run keys to achieve persistence using `HKCU\Software\Microsoft\Windows\CurrentVersion\Run`. |
| T1560.001 Archive via Utility |
MalwarePUBLOAD | PUBLOAD has used utilities such as `WinRAR` to archive data prior to exfiltration. |
| T1564.001 Hidden Files and Directories |
MalwareHIUPAN | HIUPAN has modified registry keys to ensure hidden files and extensions are not visible through the modification of `HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced`. |
| T1566.001 Spearphishing Attachment |
GroupMustang Panda | Mustang Panda has used spearphishing attachments to deliver initial access payloads. Mustang Panda has also delivered archive files such as RAR and ZIP files containing legitimate EXEs and malicious DLLs. 2025_IBM_PUBLOAD_TONESHELL_HIUPAN_CLAIMLOADER_MUSTANG PANDACSIRT CTI MUSTANG PANDA PUBLOAD TONESHELL JAN 2024Cisco Talos MUSTANG PANDA PLUGX PUBLOAD MAY 2022Google TAG Ukraine Threat Landscape March 2022IBM MUSTANG PANDA PUBLOAD CLAIMLOADER JUNE 2025Lab52 MUSTANG PANDA PUBLOAD MAY 2023Proofpoint TA416 November 2020Recorded Future REDDELTA July 2020Trend Micro MUSTANG PANDA PUBLOAD HIUPAN SEPTEMBER 2024 |
| T1574.001 DLL |
MalwareHIUPAN | HIUPAN has abused legitimate executables to side-load malicious DLLs to include the legitimate exe UsbConfig.exe. |
| T1678 Delay Execution |
MalwareHIUPAN | HIUPAN has used a config file “$.ini” to store a sleep multiplier to execute at a set interval value prior to initiating a watcher function that checks for a specific running process, that checks for removable drives and installs itself and supporting files if one is available. |
| T1680 Local Storage Discovery |
MalwarePUBLOAD | PUBLOAD has leveraged `wmic logicaldisk get` to map local network drives. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.