Asheer Malhotra, Jungsoo An, Kendall Mc. (2022, May 5). Mustang Panda deploys a new wave of malware targeting Europe. Retrieved August 4, 2025.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1027 Obfuscated Files or Information |
GroupMustang Panda | Mustang Panda has delivered initial payloads hidden using archives and encoding measures. Mustang Panda has also utilized opaque predicates in payloads to hinder analysis. 2022 November_TrendMicro_Earth Preta_Toneshell_PubloadAnomali MUSTANG PANDA October 2019Cisco Talos MUSTANG PANDA PLUGX PUBLOAD MAY 2022Crowdstrike MUSTANG PANDA June 2018Eset PlugX Korplug Mustang Panda March 2022Proofpoint TA416 Europe March 2022Proofpoint TA416 November 2020Recorded Future REDDELTA July 2020Secureworks BRONZE PRESIDENT December 2019Sophos PlugX September 2022Unit42 Bookworm Nov2015ZscalerZscaler PAKLOG CorkLog SplatCloak Splatdropper April 2025 |
| T1027 Obfuscated Files or Information |
MalwarePUBLOAD | PUBLOAD has obfuscated DLL names using the ror13AddHash32 algorithm. |
| T1027.012 LNK Icon Smuggling |
GroupMustang Panda | Mustang Panda has utilized LNK files to hide malicious scripts for execution. Mustang Panda has also leveraged LNK files that were programmed to display a PDF icon to entice the victim to click on the file to execute an office.exe binary. |
| T1033 System Owner/User Discovery |
MalwarePUBLOAD | PUBLOAD has obtained the username from an infected host. |
| T1041 Exfiltration Over C2 Channel |
GroupMustang Panda | Mustang Panda has exfiltrated stolen data and files to its C2 server. |
| T1053.005 Scheduled Task |
MalwarePUBLOAD | PUBLOAD has created scheduled tasks to maintain persistence with the command `schtasks.exe /F /Create /TN Microsoft_Licensing /sc minute /MO 1 /TR C:\\Users\\Public\\Libraries\...` |
| T1053.005 Scheduled Task |
GroupMustang Panda | Mustang Panda has created a scheduled task to execute additional malicious software, as well as maintain persistence. Mustang Panda has also created a scheduled task that creates a reverse shell. |
| T1059 Command and Scripting Interpreter |
GroupMustang Panda | Mustang Panda has utilized meterpreter shellcode. |
| T1059.003 Windows Command Shell |
GroupMustang Panda | Mustang Panda has executed HTA files via cmd.exe, and used batch scripts for collection. Mustang Panda has also utilized cmd.exe to execute commands on an infected host such as `cmd.exe /c ping.exe 8.8.8.8 -n 70&&"%temp%\FontEDL.exe"`. |
| T1059.005 Visual Basic |
GroupMustang Panda | Mustang Panda has embedded VBScript components in LNK files to download additional files and automate collection. Mustang Panda has also used VBA macros in maldocs to execute malicious DLLs. Mustang Panda also utilized a VBS Script “autorun.vbs” that created persistence through saving the VBS Script in the startup directory which would cause it to run each time the machine was turned on. |
| T1059.007 JavaScript |
GroupMustang Panda | Mustang Panda has executed a JavaScript payload utilizing wscript.exe on the endpoint. |
| T1082 System Information Discovery |
MalwarePUBLOAD | PUBLOAD has collected and sent system information including volume serial number, computer name, and system uptime to designated C2. PUBLOAD has also used several commands executed in sequence via `cmd` in a short interval to gather system information about the infected host including `systeminfo`. PUBLOAD has decrypted shellcode that collects the computer name. |
| T1083 File and Directory Discovery |
MalwarePlugX | PlugX has a module to enumerate drives and find files recursively. PlugX has also checked the path from which it is running for specific parameters prior to execution. |
| T1095 Non-Application Layer Protocol |
GroupMustang Panda | Mustang Panda has utilized TCP-based reverse shells using cmd.exe. |
| T1105 Ingress Tool Transfer |
GroupMustang Panda | Mustang Panda has downloaded additional executables following the initial infection stage. Mustang Panda has also leveraged Visual Studio Code `code.exe` and Dev Tunnels using `DevTunnel.exe` to propagate additional tools and payloads. |
| T1140 Deobfuscate/Decode Files or Information |
MalwarePlugX | PlugX decompresses and decrypts itself using the Microsoft API call RtlDecompressBuffer. PlugX has also decrypted its payloads in memory. |
| T1140 Deobfuscate/Decode Files or Information |
MalwarePUBLOAD | PUBLOAD has decoded its payload prior to execution. |
| T1204.002 Malicious File |
MalwarePlugX | PlugX has leveraged an initial executable disguised as a legitimate document to trick the target into opening it. |
| T1204.002 Malicious File |
GroupMustang Panda | Mustang Panda has sent malicious files requiring direct victim interaction to execute. Mustang Panda has also leveraged executable files that display decoy documents to the victim to provide a resemblance of legitimacy with customized themes related to the victim. 2022 November_TrendMicro_Earth Preta_Toneshell_Pubload2025_IBM_PUBLOAD_TONESHELL_HIUPAN_CLAIMLOADER_MUSTANG PANDAAnomali MUSTANG PANDA October 2019Avira Mustang Panda January 2020CSIRT CTI MUSTANG PANDA PUBLOAD TONESHELL JAN 2024Cisco Talos MUSTANG PANDA PLUGX PUBLOAD MAY 2022Crowdstrike MUSTANG PANDA June 2018EclecticIQ Mustang Panda PlugXEset PlugX Korplug Mustang Panda March 2022Google TAG Ukraine Threat Landscape March 2022IBM MUSTANG PANDA PUBLOAD CLAIMLOADER JUNE 2025Lab52 MUSTANG PANDA PUBLOAD MAY 2023Palo Alto Networks, Unit 42Proofpoint TA416 Europe March 2022Recorded Future REDDELTA July 2020Sophos Mustang Panda PLUGXSophos PlugX September 2022Trend Micro MUSTANG PANDA PUBLOAD HIUPAN SEPTEMBER 2024Trend Micro Mustang Panda Earth Preta Toneshell February 2025Unit42 Bookworm Nov2015Zscaler PAKLOG CorkLog SplatCloak Splatdropper April 2025 |
| T1547.001 Registry Run Keys / Startup Folder |
MalwarePUBLOAD | PUBLOAD has added Registry Run keys to achieve persistence using `HKCU\Software\Microsoft\Windows\CurrentVersion\Run`. |
| T1566.001 Spearphishing Attachment |
GroupMustang Panda | Mustang Panda has used spearphishing attachments to deliver initial access payloads. Mustang Panda has also delivered archive files such as RAR and ZIP files containing legitimate EXEs and malicious DLLs. 2025_IBM_PUBLOAD_TONESHELL_HIUPAN_CLAIMLOADER_MUSTANG PANDACSIRT CTI MUSTANG PANDA PUBLOAD TONESHELL JAN 2024Cisco Talos MUSTANG PANDA PLUGX PUBLOAD MAY 2022Google TAG Ukraine Threat Landscape March 2022IBM MUSTANG PANDA PUBLOAD CLAIMLOADER JUNE 2025Lab52 MUSTANG PANDA PUBLOAD MAY 2023Proofpoint TA416 November 2020Recorded Future REDDELTA July 2020Trend Micro MUSTANG PANDA PUBLOAD HIUPAN SEPTEMBER 2024 |
| T1573.001 Symmetric Cryptography |
MalwarePUBLOAD | PUBLOAD has used RC4 encryption in C2 communications. |
| T1574.001 DLL |
MalwarePUBLOAD | PUBLOAD has abused legitimate executables to side-load malicious DLLs. 2022 November_TrendMicro_Earth Preta_Toneshell_Pubload2025_IBM_PUBLOAD_TONESHELL_HIUPAN_CLAIMLOADER_MUSTANG PANDACSIRT CTI MUSTANG PANDA PUBLOAD TONESHELL JAN 2024Cisco Talos MUSTANG PANDA PLUGX PUBLOAD MAY 2022Lab52 MUSTANG PANDA PUBLOAD MAY 2023Palo Alto Networks, Unit 42PaloAlto MUSTANG PANDA PUBLOAD MARCH 2024 |
| T1574.001 DLL |
MalwarePlugX | PlugX has the ability to use DLL search order hijacking for installation on targeted systems. PlugX has also used DLL side-loading to evade anti-virus. PlugX has also used a legitimately signed executable to side-load a malicious payload within a DLL file. Cisco Talos MUSTANG PANDA PLUGX PUBLOAD MAY 2022Dell TG-3390EclecticIQ Mustang Panda PlugXEset PlugX Korplug Mustang Panda March 2022FireEye Clandestine Fox Part 2PWC Cloud Hopper Technical Annex April 2017Palo Alto PlugX June 2017Profero APT27 December 2020Proofpoint TA416 Europe March 2022Sophos Mustang Panda PLUGXSophos PlugX September 2022Stewart 2014Trend Micro DRBControl February 2020 |
| T1574.001 DLL |
GroupMustang Panda | Mustang Panda has used a legitimately signed executable to execute a malicious payload within a DLL file. Mustang Panda has abused legitimate executables to side-load malicious DLLs. 2022 November_TrendMicro_Earth Preta_Toneshell_Pubload2025_IBM_PUBLOAD_TONESHELL_HIUPAN_CLAIMLOADER_MUSTANG PANDAAnomali MUSTANG PANDA October 2019BroadcomCSIRT CTI MUSTANG PANDA PUBLOAD TONESHELL JAN 2024Cisco Talos MUSTANG PANDA PLUGX PUBLOAD MAY 2022EclecticIQ Mustang Panda PlugXEset PlugX Korplug Mustang Panda March 2022Google Threat Intelligence Group MUSTANG PANDA PLUGX August 2025IBM MUSTANG PANDA PUBLOAD CLAIMLOADER JUNE 2025Lab52 MUSTANG PANDA PUBLOAD MAY 2023Palo Alto Unit42 STATELY TAURUS TONESHELL September 2023Proofpoint TA416 November 2020Recorded Future REDDELTA July 2020Sophos PlugX September 2022Trend Micro Mustang Panda Earth Preta Toneshell February 2025Unit42 Bookworm Nov2015ZscalerZscaler PAKLOG CorkLog SplatCloak Splatdropper April 2025 |
| T1587.001 Malware |
GroupMustang Panda | Mustang Panda has developed custom malware for use in their operations. |
| T1588.002 Tool |
GroupMustang Panda | Mustang Panda has obtained and leveraged publicly-available tools for intrusion activities. |
| T1622 Debugger Evasion |
MalwarePUBLOAD | PUBLOAD has embedded debug strings with messages to distract analysts. PUBLOAD has leveraged `OutputDebugStringW` and `OutputDebugStringA` functions. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.