Ken Towne, Francis Guibernau. (2023, March 23). Emulating the Politically Motivated Chinese APT Mustang Panda. Retrieved September 10, 2025.
Not cited by any technique.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1047 Windows Management Instrumentation |
MalwareTONESHELL | TONESHELL has used WMI queries to gather information from the system. |
| T1053.005 Scheduled Task |
MalwareTONESHELL | TONESHELL has created scheduled tasks to maintain persistence. |
| T1574.001 DLL |
MalwareTONESHELL | TONESHELL has abused legitimate executables to side-load malicious DLLs. TONESHELL has also been loaded via DLL side-loading, using legitimate, signed executables to include: FastVD.exe, Bandizip.exe and gpgconf.exe. 2022 November_TrendMicro_Earth Preta_Toneshell_PubloadATTACKIQ MUSTANG PANDA TONESHELL March 2023CSIRT CTI MUSTANG PANDA PUBLOAD TONESHELL JAN 2024Palo Alto Unit42 STATELY TAURUS TONESHELL September 2023Trend Micro Mustang Panda Earth Preta TONESHELL June 2023Trend Micro Mustang Panda Earth Preta Toneshell February 2025Zscaler |
| T1680 Local Storage Discovery |
MalwareTONESHELL | TONESHELL has retrieved the disk serial number of the device using WMI query `SELECT volumeserialnumber FROM win32_logicaldisk where Name =’C:` to identify the victim machine. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.