Alexandre Cote Cyr. (2022, March 23). Mustang Panda’s Hodur: Old tricks, new Korplug variant. Retrieved September 9, 2025.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1012 Query Registry |
MalwarePlugX | PlugX can enumerate and query for information contained within the Windows Registry. |
| T1016 System Network Configuration Discovery |
MalwarePlugX | PlugX has captured victim IP address details of the targeted machine. |
| T1027 Obfuscated Files or Information |
GroupMustang Panda | Mustang Panda has delivered initial payloads hidden using archives and encoding measures. Mustang Panda has also utilized opaque predicates in payloads to hinder analysis. 2022 November_TrendMicro_Earth Preta_Toneshell_PubloadAnomali MUSTANG PANDA October 2019Cisco Talos MUSTANG PANDA PLUGX PUBLOAD MAY 2022Crowdstrike MUSTANG PANDA June 2018Eset PlugX Korplug Mustang Panda March 2022Proofpoint TA416 Europe March 2022Proofpoint TA416 November 2020Recorded Future REDDELTA July 2020Secureworks BRONZE PRESIDENT December 2019Sophos PlugX September 2022Unit42 Bookworm Nov2015ZscalerZscaler PAKLOG CorkLog SplatCloak Splatdropper April 2025 |
| T1027.001 Binary Padding |
MalwarePlugX | PlugX has utilized junk code and opaque predicates in payloads to hinder analysis. |
| T1027.007 Dynamic API Resolution |
GroupMustang Panda | Mustang Panda has leveraged obfuscated Windows API function calls that were concealed as unique names, or hashes of the Windows API. |
| T1027.007 Dynamic API Resolution |
MalwarePlugX | PlugX has leveraged obfuscated Windows API function calls that were concealed as unique names, or hashes of the Windows API. |
| T1027.013 Encrypted/Encoded File |
MalwarePlugX | PlugX has leveraged XOR encryption with the key of 123456789. |
| T1027.016 Junk Code Insertion |
GroupMustang Panda | Mustang Panda has used junk code within their DLL files to hinder analysis. |
| T1033 System Owner/User Discovery |
MalwarePlugX | PlugX has the ability to gather the username from the victim’s machine. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwarePlugX | PlugX has been disguised as legitimate Adobe and PotPlayer files. PlugX has also imitated legitimate software directories and file names through the creation and storage of a legitimate EXE and the malicious DLLs. |
| T1053.005 Scheduled Task |
MalwarePlugX | PlugX has created a scheduled task to execute additional malicious software, as well as maintain persistence. |
| T1059.003 Windows Command Shell |
MalwarePlugX | PlugX allows actors to spawn a reverse shell on a victim. |
| T1070 Indicator Removal |
GroupMustang Panda | Mustang Panda has deleted registry keys that store data and maintained persistence. |
| T1070.004 File Deletion |
MalwarePlugX | PlugX has the remove itself and other artifacts. |
| T1070.009 Clear Persistence |
MalwarePlugX | PlugX has deleted registry keys that store data and maintained persistence. |
| T1071.001 Web Protocols |
MalwarePlugX | PlugX can be configured to use HTTP for command and control. PlugX has also used HTTPS for C2. |
| T1082 System Information Discovery |
MalwarePlugX | PlugX has collected system information including OS version, processor information, RAM size, location, host name, IP, and screen size of the infected host. |
| T1083 File and Directory Discovery |
MalwarePlugX | PlugX has a module to enumerate drives and find files recursively. PlugX has also checked the path from which it is running for specific parameters prior to execution. |
| T1095 Non-Application Layer Protocol |
MalwarePlugX | PlugX can be configured to use raw TCP or UDP for command and control. |
| T1105 Ingress Tool Transfer |
GroupMustang Panda | Mustang Panda has downloaded additional executables following the initial infection stage. Mustang Panda has also leveraged Visual Studio Code `code.exe` and Dev Tunnels using `DevTunnel.exe` to propagate additional tools and payloads. |
| T1106 Native API |
MalwarePlugX | PlugX can use the Windows API functions `GetProcAddress`, `LoadLibrary`, and `CreateProcess` to execute another process. |
| T1106 Native API |
GroupMustang Panda | Mustang Panda has used various Windows API calls during execution and defense evasion. 2022 November_TrendMicro_Earth Preta_Toneshell_Pubload2025_IBM_PUBLOAD_TONESHELL_HIUPAN_CLAIMLOADER_MUSTANG PANDABroadcomEset PlugX Korplug Mustang Panda March 2022Google Threat Intelligence Group MUSTANG PANDA PLUGX August 2025IBM MUSTANG PANDA PUBLOAD CLAIMLOADER JUNE 2025Lab52 MUSTANG PANDA PUBLOAD MAY 2023Palo Alto Networks, Unit 42Sophos Mustang Panda PLUGXTrend Micro Mustang Panda Earth Preta Toneshell February 2025ZscalerZscaler PAKLOG CorkLog SplatCloak Splatdropper April 2025 |
| T1112 Modify Registry |
MalwarePlugX | PlugX has a module to create, delete, or modify Registry keys. |
| T1124 System Time Discovery |
MalwarePlugX | PlugX has identified system time through its GetSystemInfo command. |
| T1129 Shared Modules |
GroupMustang Panda | Mustang Panda has leveraged `LoadLibrary` to load DLLs. |
| T1135 Network Share Discovery |
MalwarePlugX | PlugX has a module to enumerate network shares. |
| T1140 Deobfuscate/Decode Files or Information |
MalwarePlugX | PlugX decompresses and decrypts itself using the Microsoft API call RtlDecompressBuffer. PlugX has also decrypted its payloads in memory. |
| T1204.002 Malicious File |
GroupMustang Panda | Mustang Panda has sent malicious files requiring direct victim interaction to execute. Mustang Panda has also leveraged executable files that display decoy documents to the victim to provide a resemblance of legitimacy with customized themes related to the victim. 2022 November_TrendMicro_Earth Preta_Toneshell_Pubload2025_IBM_PUBLOAD_TONESHELL_HIUPAN_CLAIMLOADER_MUSTANG PANDAAnomali MUSTANG PANDA October 2019Avira Mustang Panda January 2020CSIRT CTI MUSTANG PANDA PUBLOAD TONESHELL JAN 2024Cisco Talos MUSTANG PANDA PLUGX PUBLOAD MAY 2022Crowdstrike MUSTANG PANDA June 2018EclecticIQ Mustang Panda PlugXEset PlugX Korplug Mustang Panda March 2022Google TAG Ukraine Threat Landscape March 2022IBM MUSTANG PANDA PUBLOAD CLAIMLOADER JUNE 2025Lab52 MUSTANG PANDA PUBLOAD MAY 2023Palo Alto Networks, Unit 42Proofpoint TA416 Europe March 2022Recorded Future REDDELTA July 2020Sophos Mustang Panda PLUGXSophos PlugX September 2022Trend Micro MUSTANG PANDA PUBLOAD HIUPAN SEPTEMBER 2024Trend Micro Mustang Panda Earth Preta Toneshell February 2025Unit42 Bookworm Nov2015Zscaler PAKLOG CorkLog SplatCloak Splatdropper April 2025 |
| T1480.002 Mutual Exclusion |
MalwarePlugX | PlugX has leveraged a mutex in its infection process. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwarePlugX | PlugX adds Run key entries in the Registry to establish persistence. PlugX has established persistence via the registry keys `HKCU\Software\Microsoft\Windows\CurrentVersion\Run` and `HKLM\Software\Microsoft\Windows\CurrentVersion\Run`. |
| T1564.001 Hidden Files and Directories |
GroupMustang Panda | Mustang Panda's PlugX variant has created a hidden folder on USB drives named |
| T1564.001 Hidden Files and Directories |
MalwarePlugX | PlugX can modify the characteristics of folders to hide them from the compromised user. PlugX has also modified file attributes to hidden and system. |
| T1564.003 Hidden Window |
MalwarePlugX | PlugX has the ability to execute a command on a hidden desktop. |
| T1573.001 Symmetric Cryptography |
GroupMustang Panda | Mustang Panda has encrypted C2 communications with RC4. Mustang Panda has also leveraged encryption and compression algorithms to obfuscate the traffic between the system and C2 server, methods observed included RC4, AES, XOR with 0x5a, and LZO. |
| T1573.001 Symmetric Cryptography |
MalwarePlugX | PlugX can use RC4 encryption in C2 communications. |
| T1574.001 DLL |
GroupMustang Panda | Mustang Panda has used a legitimately signed executable to execute a malicious payload within a DLL file. Mustang Panda has abused legitimate executables to side-load malicious DLLs. 2022 November_TrendMicro_Earth Preta_Toneshell_Pubload2025_IBM_PUBLOAD_TONESHELL_HIUPAN_CLAIMLOADER_MUSTANG PANDAAnomali MUSTANG PANDA October 2019BroadcomCSIRT CTI MUSTANG PANDA PUBLOAD TONESHELL JAN 2024Cisco Talos MUSTANG PANDA PLUGX PUBLOAD MAY 2022EclecticIQ Mustang Panda PlugXEset PlugX Korplug Mustang Panda March 2022Google Threat Intelligence Group MUSTANG PANDA PLUGX August 2025IBM MUSTANG PANDA PUBLOAD CLAIMLOADER JUNE 2025Lab52 MUSTANG PANDA PUBLOAD MAY 2023Palo Alto Unit42 STATELY TAURUS TONESHELL September 2023Proofpoint TA416 November 2020Recorded Future REDDELTA July 2020Sophos PlugX September 2022Trend Micro Mustang Panda Earth Preta Toneshell February 2025Unit42 Bookworm Nov2015ZscalerZscaler PAKLOG CorkLog SplatCloak Splatdropper April 2025 |
| T1574.001 DLL |
MalwarePlugX | PlugX has the ability to use DLL search order hijacking for installation on targeted systems. PlugX has also used DLL side-loading to evade anti-virus. PlugX has also used a legitimately signed executable to side-load a malicious payload within a DLL file. Cisco Talos MUSTANG PANDA PLUGX PUBLOAD MAY 2022Dell TG-3390EclecticIQ Mustang Panda PlugXEset PlugX Korplug Mustang Panda March 2022FireEye Clandestine Fox Part 2PWC Cloud Hopper Technical Annex April 2017Palo Alto PlugX June 2017Profero APT27 December 2020Proofpoint TA416 Europe March 2022Sophos Mustang Panda PLUGXSophos PlugX September 2022Stewart 2014Trend Micro DRBControl February 2020 |
| T1587.001 Malware |
GroupMustang Panda | Mustang Panda has developed custom malware for use in their operations. |
| T1614 System Location Discovery |
MalwarePlugX | PlugX has obtained the location of the victim device by leveraging `GetSystemDefaultLCID`. |
| T1620 Reflective Code Loading |
MalwarePlugX | PlugX has loaded its payload into memory. |
| T1678 Delay Execution |
GroupMustang Panda | Mustang Panda has delayed the execution of payloads leveraging ping echo requests `cmd /c ping 8.8.8.8 -n 70&&"%temp%\<legitimate executable>"`. |
| T1680 Local Storage Discovery |
MalwarePlugX | PlugX has collected a list of all mapped drives on the infected host. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.