ATT&CKReferencesCisco Talos MUSTANG PANDA PLUGX PUBLOAD MAY 2022

Cisco Talos MUSTANG PANDA PLUGX PUBLOAD MAY 2022

Asheer Malhotra, Jungsoo An, Kendall Mc. (2022, May 5). Mustang Panda deploys a new wave of malware targeting Europe. Retrieved August 4, 2025.

Open the source

Techniques0

Not cited by any technique.

Groups1

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples28

TechniqueUsed byProcedure example
T1027
Obfuscated Files or Information
GroupMustang Panda

Mustang Panda has delivered initial payloads hidden using archives and encoding measures. Mustang Panda has also utilized opaque predicates in payloads to hinder analysis.

T1027
Obfuscated Files or Information
MalwarePUBLOAD

PUBLOAD has obfuscated DLL names using the ror13AddHash32 algorithm.

T1027.012
LNK Icon Smuggling
GroupMustang Panda

Mustang Panda has utilized LNK files to hide malicious scripts for execution. Mustang Panda has also leveraged LNK files that were programmed to display a PDF icon to entice the victim to click on the file to execute an office.exe binary.

T1033
System Owner/User Discovery
MalwarePUBLOAD

PUBLOAD has obtained the username from an infected host.

T1041
Exfiltration Over C2 Channel
GroupMustang Panda

Mustang Panda has exfiltrated stolen data and files to its C2 server.

T1053.005
Scheduled Task
MalwarePUBLOAD

PUBLOAD has created scheduled tasks to maintain persistence with the command `schtasks.exe /F /Create /TN Microsoft_Licensing /sc minute /MO 1 /TR C:\\Users\\Public\\Libraries\...`

T1053.005
Scheduled Task
GroupMustang Panda

Mustang Panda has created a scheduled task to execute additional malicious software, as well as maintain persistence. Mustang Panda has also created a scheduled task that creates a reverse shell.

T1059
Command and Scripting Interpreter
GroupMustang Panda

Mustang Panda has utilized meterpreter shellcode.

T1059.003
Windows Command Shell
GroupMustang Panda

Mustang Panda has executed HTA files via cmd.exe, and used batch scripts for collection. Mustang Panda has also utilized cmd.exe to execute commands on an infected host such as `cmd.exe /c ping.exe 8.8.8.8 -n 70&&"%temp%\FontEDL.exe"`.

T1059.005
Visual Basic
GroupMustang Panda

Mustang Panda has embedded VBScript components in LNK files to download additional files and automate collection. Mustang Panda has also used VBA macros in maldocs to execute malicious DLLs. Mustang Panda also utilized a VBS Script “autorun.vbs” that created persistence through saving the VBS Script in the startup directory which would cause it to run each time the machine was turned on.

T1059.007
JavaScript
GroupMustang Panda

Mustang Panda has executed a JavaScript payload utilizing wscript.exe on the endpoint.

T1082
System Information Discovery
MalwarePUBLOAD

PUBLOAD has collected and sent system information including volume serial number, computer name, and system uptime to designated C2. PUBLOAD has also used several commands executed in sequence via `cmd` in a short interval to gather system information about the infected host including `systeminfo`. PUBLOAD has decrypted shellcode that collects the computer name.

T1083
File and Directory Discovery
MalwarePlugX

PlugX has a module to enumerate drives and find files recursively. PlugX has also checked the path from which it is running for specific parameters prior to execution.

T1095
Non-Application Layer Protocol
GroupMustang Panda

Mustang Panda has utilized TCP-based reverse shells using cmd.exe.

T1105
Ingress Tool Transfer
GroupMustang Panda

Mustang Panda has downloaded additional executables following the initial infection stage. Mustang Panda has also leveraged Visual Studio Code `code.exe` and Dev Tunnels using `DevTunnel.exe` to propagate additional tools and payloads.

T1140
Deobfuscate/Decode Files or Information
MalwarePlugX

PlugX decompresses and decrypts itself using the Microsoft API call RtlDecompressBuffer. PlugX has also decrypted its payloads in memory.

T1140
Deobfuscate/Decode Files or Information
MalwarePUBLOAD

PUBLOAD has decoded its payload prior to execution.

T1204.002
Malicious File
MalwarePlugX

PlugX has leveraged an initial executable disguised as a legitimate document to trick the target into opening it.

T1204.002
Malicious File
GroupMustang Panda

Mustang Panda has sent malicious files requiring direct victim interaction to execute. Mustang Panda has also leveraged executable files that display decoy documents to the victim to provide a resemblance of legitimacy with customized themes related to the victim.

T1547.001
Registry Run Keys / Startup Folder
MalwarePUBLOAD

PUBLOAD has added Registry Run keys to achieve persistence using `HKCU\Software\Microsoft\Windows\CurrentVersion\Run`.

T1566.001
Spearphishing Attachment
GroupMustang Panda

Mustang Panda has used spearphishing attachments to deliver initial access payloads. Mustang Panda has also delivered archive files such as RAR and ZIP files containing legitimate EXEs and malicious DLLs.

T1573.001
Symmetric Cryptography
MalwarePUBLOAD

PUBLOAD has used RC4 encryption in C2 communications.

T1574.001
DLL
MalwarePUBLOAD

PUBLOAD has abused legitimate executables to side-load malicious DLLs.

T1574.001
DLL
MalwarePlugX

PlugX has the ability to use DLL search order hijacking for installation on targeted systems. PlugX has also used DLL side-loading to evade anti-virus. PlugX has also used a legitimately signed executable to side-load a malicious payload within a DLL file.

T1574.001
DLL
GroupMustang Panda

Mustang Panda has used a legitimately signed executable to execute a malicious payload within a DLL file. Mustang Panda has abused legitimate executables to side-load malicious DLLs.

T1587.001
Malware
GroupMustang Panda

Mustang Panda has developed custom malware for use in their operations.

T1588.002
Tool
GroupMustang Panda

Mustang Panda has obtained and leveraged publicly-available tools for intrusion activities.

T1622
Debugger Evasion
MalwarePUBLOAD

PUBLOAD has embedded debug strings with messages to distract analysts. PUBLOAD has leveraged `OutputDebugStringW` and `OutputDebugStringA` functions.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.