ATT&CKReferencesEset PlugX Korplug Mustang Panda March 2022

Eset PlugX Korplug Mustang Panda March 2022

Alexandre Cote Cyr. (2022, March 23). Mustang Panda’s Hodur: Old tricks, new Korplug variant. Retrieved September 9, 2025.

Open the source

Techniques0

Not cited by any technique.

Groups1

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples42

TechniqueUsed byProcedure example
T1012
Query Registry
MalwarePlugX

PlugX can enumerate and query for information contained within the Windows Registry.

T1016
System Network Configuration Discovery
MalwarePlugX

PlugX has captured victim IP address details of the targeted machine.

T1027
Obfuscated Files or Information
GroupMustang Panda

Mustang Panda has delivered initial payloads hidden using archives and encoding measures. Mustang Panda has also utilized opaque predicates in payloads to hinder analysis.

T1027.001
Binary Padding
MalwarePlugX

PlugX has utilized junk code and opaque predicates in payloads to hinder analysis.

T1027.007
Dynamic API Resolution
GroupMustang Panda

Mustang Panda has leveraged obfuscated Windows API function calls that were concealed as unique names, or hashes of the Windows API.

T1027.007
Dynamic API Resolution
MalwarePlugX

PlugX has leveraged obfuscated Windows API function calls that were concealed as unique names, or hashes of the Windows API.

T1027.013
Encrypted/Encoded File
MalwarePlugX

PlugX has leveraged XOR encryption with the key of 123456789.

T1027.016
Junk Code Insertion
GroupMustang Panda

Mustang Panda has used junk code within their DLL files to hinder analysis.

T1033
System Owner/User Discovery
MalwarePlugX

PlugX has the ability to gather the username from the victim’s machine.

T1036.005
Match Legitimate Resource Name or Location
MalwarePlugX

PlugX has been disguised as legitimate Adobe and PotPlayer files. PlugX has also imitated legitimate software directories and file names through the creation and storage of a legitimate EXE and the malicious DLLs.

T1053.005
Scheduled Task
MalwarePlugX

PlugX has created a scheduled task to execute additional malicious software, as well as maintain persistence.

T1059.003
Windows Command Shell
MalwarePlugX

PlugX allows actors to spawn a reverse shell on a victim.

T1070
Indicator Removal
GroupMustang Panda

Mustang Panda has deleted registry keys that store data and maintained persistence.

T1070.004
File Deletion
MalwarePlugX

PlugX has the remove itself and other artifacts.

T1070.009
Clear Persistence
MalwarePlugX

PlugX has deleted registry keys that store data and maintained persistence.

T1071.001
Web Protocols
MalwarePlugX

PlugX can be configured to use HTTP for command and control. PlugX has also used HTTPS for C2.

T1082
System Information Discovery
MalwarePlugX

PlugX has collected system information including OS version, processor information, RAM size, location, host name, IP, and screen size of the infected host.

T1083
File and Directory Discovery
MalwarePlugX

PlugX has a module to enumerate drives and find files recursively. PlugX has also checked the path from which it is running for specific parameters prior to execution.

T1095
Non-Application Layer Protocol
MalwarePlugX

PlugX can be configured to use raw TCP or UDP for command and control.

T1105
Ingress Tool Transfer
GroupMustang Panda

Mustang Panda has downloaded additional executables following the initial infection stage. Mustang Panda has also leveraged Visual Studio Code `code.exe` and Dev Tunnels using `DevTunnel.exe` to propagate additional tools and payloads.

T1106
Native API
MalwarePlugX

PlugX can use the Windows API functions `GetProcAddress`, `LoadLibrary`, and `CreateProcess` to execute another process.

T1106
Native API
GroupMustang Panda

Mustang Panda has used various Windows API calls during execution and defense evasion.

T1112
Modify Registry
MalwarePlugX

PlugX has a module to create, delete, or modify Registry keys.

T1124
System Time Discovery
MalwarePlugX

PlugX has identified system time through its GetSystemInfo command.

T1129
Shared Modules
GroupMustang Panda

Mustang Panda has leveraged `LoadLibrary` to load DLLs.

T1135
Network Share Discovery
MalwarePlugX

PlugX has a module to enumerate network shares.

T1140
Deobfuscate/Decode Files or Information
MalwarePlugX

PlugX decompresses and decrypts itself using the Microsoft API call RtlDecompressBuffer. PlugX has also decrypted its payloads in memory.

T1204.002
Malicious File
GroupMustang Panda

Mustang Panda has sent malicious files requiring direct victim interaction to execute. Mustang Panda has also leveraged executable files that display decoy documents to the victim to provide a resemblance of legitimacy with customized themes related to the victim.

T1480.002
Mutual Exclusion
MalwarePlugX

PlugX has leveraged a mutex in its infection process.

T1547.001
Registry Run Keys / Startup Folder
MalwarePlugX

PlugX adds Run key entries in the Registry to establish persistence. PlugX has established persistence via the registry keys `HKCU\Software\Microsoft\Windows\CurrentVersion\Run` and `HKLM\Software\Microsoft\Windows\CurrentVersion\Run`.

T1564.001
Hidden Files and Directories
GroupMustang Panda

Mustang Panda's PlugX variant has created a hidden folder on USB drives named RECYCLE.BIN to store malicious executables and collected data. Mustang Panda has also modified file attributes to `hidden` and `system`.

T1564.001
Hidden Files and Directories
MalwarePlugX

PlugX can modify the characteristics of folders to hide them from the compromised user. PlugX has also modified file attributes to hidden and system.

T1564.003
Hidden Window
MalwarePlugX

PlugX has the ability to execute a command on a hidden desktop.

T1573.001
Symmetric Cryptography
GroupMustang Panda

Mustang Panda has encrypted C2 communications with RC4. Mustang Panda has also leveraged encryption and compression algorithms to obfuscate the traffic between the system and C2 server, methods observed included RC4, AES, XOR with 0x5a, and LZO.

T1573.001
Symmetric Cryptography
MalwarePlugX

PlugX can use RC4 encryption in C2 communications.

T1574.001
DLL
GroupMustang Panda

Mustang Panda has used a legitimately signed executable to execute a malicious payload within a DLL file. Mustang Panda has abused legitimate executables to side-load malicious DLLs.

T1574.001
DLL
MalwarePlugX

PlugX has the ability to use DLL search order hijacking for installation on targeted systems. PlugX has also used DLL side-loading to evade anti-virus. PlugX has also used a legitimately signed executable to side-load a malicious payload within a DLL file.

T1587.001
Malware
GroupMustang Panda

Mustang Panda has developed custom malware for use in their operations.

T1614
System Location Discovery
MalwarePlugX

PlugX has obtained the location of the victim device by leveraging `GetSystemDefaultLCID`.

T1620
Reflective Code Loading
MalwarePlugX

PlugX has loaded its payload into memory.

T1678
Delay Execution
GroupMustang Panda

Mustang Panda has delayed the execution of payloads leveraging ping echo requests `cmd /c ping 8.8.8.8 -n 70&&"%temp%\<legitimate executable>"`.

T1680
Local Storage Discovery
MalwarePlugX

PlugX has collected a list of all mapped drives on the infected host.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.