T1027 Obfuscated Files or Information |
GroupMustang Panda |
Mustang Panda has delivered initial payloads hidden using archives and encoding measures. Mustang Panda has also utilized opaque predicates in payloads to hinder analysis. |
T1036.005 Match Legitimate Resource Name or Location |
MalwarePlugX |
PlugX has been disguised as legitimate Adobe and PotPlayer files. PlugX has also imitated legitimate software directories and file names through the creation and storage of a legitimate EXE and the malicious DLLs. |
T1036.008 Masquerade File Type |
GroupMustang Panda |
Mustang Panda has masqueraded malicious executables as legitimate files that download PlugX malware. |
T1041 Exfiltration Over C2 Channel |
GroupMustang Panda |
Mustang Panda has exfiltrated stolen data and files to its C2 server. |
T1041 Exfiltration Over C2 Channel |
MalwarePlugX |
PlugX has exfiltrated stolen data and files to its C2 server. |
T1059.003 Windows Command Shell |
MalwarePlugX |
PlugX allows actors to spawn a reverse shell on a victim. |
T1105 Ingress Tool Transfer |
GroupMustang Panda |
Mustang Panda has downloaded additional executables following the initial infection stage. Mustang Panda has also leveraged Visual Studio Code `code.exe` and Dev Tunnels using `DevTunnel.exe` to propagate additional tools and payloads. |
T1204.002 Malicious File |
GroupMustang Panda |
Mustang Panda has sent malicious files requiring direct victim interaction to execute. Mustang Panda has also leveraged executable files that display decoy documents to the victim to provide a resemblance of legitimacy with customized themes related to the victim. |
T1553.002 Code Signing |
GroupMustang Panda |
Mustang Panda has used valid legitimate digital signatures and certificates to evade detection. |
T1574.001 DLL |
MalwarePlugX |
PlugX has the ability to use DLL search order hijacking for installation on targeted systems. PlugX has also used DLL side-loading to evade anti-virus. PlugX has also used a legitimately signed executable to side-load a malicious payload within a DLL file. |
T1574.001 DLL |
GroupMustang Panda |
Mustang Panda has used a legitimately signed executable to execute a malicious payload within a DLL file. Mustang Panda has abused legitimate executables to side-load malicious DLLs. |
T1620 Reflective Code Loading |
MalwarePlugX |
PlugX has loaded its payload into memory. |
T1678 Delay Execution |
GroupMustang Panda |
Mustang Panda has delayed the execution of payloads leveraging ping echo requests `cmd /c ping 8.8.8.8 -n 70&&"%temp%\<legitimate executable>"`. |