Robert Falcone. (2025, February 20). Stately Taurus Activity in Southeast Asia Links to Bookworm Malware. Retrieved July 21, 2025.
Not cited by any technique.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1001.003 Protocol or Service Impersonation |
MalwarePUBLOAD | PUBLOAD has modified HTTP POST requests to resemble legitimate communications. PUBLOAD used FakeTLS headers in network packets to impersonate various versions of TLS protocols to blend in with legitimate network traffic. PUBLOAD has utilized FakeTLS headers with the bytes 17 03 03. |
| T1001.003 Protocol or Service Impersonation |
MalwareBOOKWORM | BOOKWORM has modified HTTP POST requests to resemble legitimate communications. |
| T1027.013 Encrypted/Encoded File |
MalwareBOOKWORM | BOOKWORM has utilized Base64 encoding to obfuscate its payload. |
| T1027.015 Compression |
MalwarePUBLOAD | PUBLOAD has been delivered as compressed files within ZIP files to victims. |
| T1070.006 Timestomp |
GroupMustang Panda | Mustang Panda has modified file timestamps from the export address table (EAT) in malware to make it difficult to identify creation times. |
| T1070.006 Timestomp |
MalwareBOOKWORM | BOOKWORM has modified file timestamps from the export address table (EAT) to make it difficult to discern when the module was created. |
| T1071.001 Web Protocols |
MalwarePUBLOAD | PUBLOAD has communicated via `curl` over HTTP to identify device IP data. PUBLOAD has also utilized HTTP for a command-and-control protocol through HTTP POST. PUBLOAD has also leveraged HTTPS for C2. |
| T1071.001 Web Protocols |
MalwareBOOKWORM | BOOKWORM has communicated with its C2 via HTTP POST requests. |
| T1105 Ingress Tool Transfer |
MalwarePUBLOAD | PUBLOAD has acted as a stager that can download the next-stage payload from its C2 server. PUBLOAD has also delivered FDMTP as a secondary control tool and PTSOCKET for exfiltration to some infected systems. |
| T1106 Native API |
MalwarePUBLOAD | PUBLOAD has used various Windows API calls during execution, when establishing persistence and defense evasion. PUBLOAD stager leveraged Windows API functions with callback including `GrayStringW`, `EnumDateFormatsA`, and `LineDDA` to bypass anti-virus monitoring. PUBLOAD has also utilized other native windows API functions with callback functions such as `EnumChildWindows` and `EnumSystemLanguageGroupsA`. |
| T1106 Native API |
MalwareBOOKWORM | BOOKWORM has used various Windows API calls during execution and defense evasion. BOOKWORM has created a buffer on the heap using `HeapCreate` and `HeapAlloc` which allows for copying of shell code and then execution on the heap is initiated through callback function of legitimate API functions such as `EnumChildWindows` or `EnumSystemLanguageGroupsA`. |
| T1106 Native API |
MalwareTONESHELL | TONESHELL has utilized Native Windows API functions such as `WriteProcessMemory` and `CreateRemoteThreadEx`. TONESHELL has also utilized Windows API functions for creating seed values including `CoCreateGuid` and `GetTickCount`. TONESHELL has leveraged the legitimate API function `EnumSystemLocalesA` to run its shellcode through the callback function. |
| T1106 Native API |
GroupMustang Panda | Mustang Panda has used various Windows API calls during execution and defense evasion. 2022 November_TrendMicro_Earth Preta_Toneshell_Pubload2025_IBM_PUBLOAD_TONESHELL_HIUPAN_CLAIMLOADER_MUSTANG PANDABroadcomEset PlugX Korplug Mustang Panda March 2022Google Threat Intelligence Group MUSTANG PANDA PLUGX August 2025IBM MUSTANG PANDA PUBLOAD CLAIMLOADER JUNE 2025Lab52 MUSTANG PANDA PUBLOAD MAY 2023Palo Alto Networks, Unit 42Sophos Mustang Panda PLUGXTrend Micro Mustang Panda Earth Preta Toneshell February 2025ZscalerZscaler PAKLOG CorkLog SplatCloak Splatdropper April 2025 |
| T1140 Deobfuscate/Decode Files or Information |
MalwarePUBLOAD | PUBLOAD has decoded its payload prior to execution. |
| T1140 Deobfuscate/Decode Files or Information |
GroupMustang Panda | Mustang Panda has the ability to decrypt its payload prior to execution. Mustang Panda has also utilized RC4 encryption for malicious payloads. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareBOOKWORM | BOOKWORM has decoded its Base64 encoded payload prior to execution. BOOKWORM has also encrypted files with RC4 and has decrypted its payload prior to execution. |
| T1204.002 Malicious File |
GroupMustang Panda | Mustang Panda has sent malicious files requiring direct victim interaction to execute. Mustang Panda has also leveraged executable files that display decoy documents to the victim to provide a resemblance of legitimacy with customized themes related to the victim. 2022 November_TrendMicro_Earth Preta_Toneshell_Pubload2025_IBM_PUBLOAD_TONESHELL_HIUPAN_CLAIMLOADER_MUSTANG PANDAAnomali MUSTANG PANDA October 2019Avira Mustang Panda January 2020CSIRT CTI MUSTANG PANDA PUBLOAD TONESHELL JAN 2024Cisco Talos MUSTANG PANDA PLUGX PUBLOAD MAY 2022Crowdstrike MUSTANG PANDA June 2018EclecticIQ Mustang Panda PlugXEset PlugX Korplug Mustang Panda March 2022Google TAG Ukraine Threat Landscape March 2022IBM MUSTANG PANDA PUBLOAD CLAIMLOADER JUNE 2025Lab52 MUSTANG PANDA PUBLOAD MAY 2023Palo Alto Networks, Unit 42Proofpoint TA416 Europe March 2022Recorded Future REDDELTA July 2020Sophos Mustang Panda PLUGXSophos PlugX September 2022Trend Micro MUSTANG PANDA PUBLOAD HIUPAN SEPTEMBER 2024Trend Micro Mustang Panda Earth Preta Toneshell February 2025Unit42 Bookworm Nov2015Zscaler PAKLOG CorkLog SplatCloak Splatdropper April 2025 |
| T1553.002 Code Signing |
GroupMustang Panda | Mustang Panda has used valid legitimate digital signatures and certificates to evade detection. |
| T1574.001 DLL |
MalwarePUBLOAD | PUBLOAD has abused legitimate executables to side-load malicious DLLs. 2022 November_TrendMicro_Earth Preta_Toneshell_Pubload2025_IBM_PUBLOAD_TONESHELL_HIUPAN_CLAIMLOADER_MUSTANG PANDACSIRT CTI MUSTANG PANDA PUBLOAD TONESHELL JAN 2024Cisco Talos MUSTANG PANDA PLUGX PUBLOAD MAY 2022Lab52 MUSTANG PANDA PUBLOAD MAY 2023Palo Alto Networks, Unit 42PaloAlto MUSTANG PANDA PUBLOAD MARCH 2024 |
| T1574.001 DLL |
MalwareBOOKWORM | BOOKWORM has used DLL side-loading to execute the malicious payload. BOOKWORM has also side-loaded DLL components into a legitimate process, including Microsoft Malware Protection `MsMpEng.exe` and Kaspersky Anti-Virus `ushata.exe`. |
| T1583.001 Domains |
GroupMustang Panda | Mustang Panda has acquired C2 domains prior to operations. CSIRT CTI MUSTANG PANDA PUBLOAD TONESHELL JAN 2024Google Threat Intelligence Group MUSTANG PANDA PLUGX August 2025Lab52 MUSTANG PANDA PUBLOAD MAY 2023McAfee Dianxun March 2021Palo Alto Networks, Unit 42Recorded Future REDDELTA July 2020Secureworks BRONZE PRESIDENT December 2019Trend Micro Mustang Panda Earth Preta Toneshell February 2025Unit42 Bookworm Nov2015 |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.