ATT&CKReferencesATTACKIQ MUSTANG PANDA TONESHELL March 2023

ATTACKIQ MUSTANG PANDA TONESHELL March 2023

Ken Towne, Francis Guibernau. (2023, March 23). Emulating the Politically Motivated Chinese APT Mustang Panda. Retrieved September 10, 2025.

Open the source

Techniques0

Not cited by any technique.

Groups1

Software1

Campaigns0

None recorded.

Procedure examples4

TechniqueUsed byProcedure example
T1047
Windows Management Instrumentation
MalwareTONESHELL

TONESHELL has used WMI queries to gather information from the system.

T1053.005
Scheduled Task
MalwareTONESHELL

TONESHELL has created scheduled tasks to maintain persistence.

T1574.001
DLL
MalwareTONESHELL

TONESHELL has abused legitimate executables to side-load malicious DLLs. TONESHELL has also been loaded via DLL side-loading, using legitimate, signed executables to include: FastVD.exe, Bandizip.exe and gpgconf.exe.

T1680
Local Storage Discovery
MalwareTONESHELL

TONESHELL has retrieved the disk serial number of the device using WMI query `SELECT volumeserialnumber FROM win32_logicaldisk where Name =’C:` to identify the victim machine.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.