Lior Rochberger, Tom Fakterman, Robert Falcone. (2023, September 22). Cyberespionage Attacks Against Southeast Asian Government Linked to Stately Taurus, Aka Mustang Panda. Retrieved September 9, 2025.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1003 OS Credential Dumping |
GroupMustang Panda | Mustang Panda utilized “Hdump” to dump credentials from memory. |
| T1003.001 LSASS Memory |
GroupMustang Panda | Mustang Panda has harvested credentials from memory of lssas.exe with Mimikatz. |
| T1003.003 NTDS |
GroupMustang Panda | Mustang Panda has used vssadmin to create a volume shadow copy and retrieve the NTDS.dit file. Mustang Panda has also used |
| T1003.006 DCSync |
GroupMustang Panda | Mustang Panda has leveraged Mimikatz DCSync feature to obtain user credentials. |
| T1018 Remote System Discovery |
GroupMustang Panda | Mustang Panda has queried Active Directory for computers using AdFind. Mustang Panda has also utilized SharpNBTScan to scan the victim environment. |
| T1036.004 Masquerade Task or Service |
MalwareTONESHELL | TONESHELL has masqueraded as the legitimate Windows utility service DISMsrv (Dism Images Servicing Utility Service). |
| T1046 Network Service Discovery |
GroupMustang Panda | Mustang Panda has leveraged NBTscan to scan IP networks. |
| T1048.003 Exfiltration Over Unencrypted Non-C2 Protocol |
GroupMustang Panda | Mustang Panda has used FTP to exfiltrate archive files. |
| T1053.005 Scheduled Task |
MalwareTONESHELL | TONESHELL has created scheduled tasks to maintain persistence. |
| T1056.001 Keylogging |
MalwareTONESHELL | TONESHELL has capabilities to conduct keylogging. |
| T1059.005 Visual Basic |
GroupMustang Panda | Mustang Panda has embedded VBScript components in LNK files to download additional files and automate collection. Mustang Panda has also used VBA macros in maldocs to execute malicious DLLs. Mustang Panda also utilized a VBS Script “autorun.vbs” that created persistence through saving the VBS Script in the startup directory which would cause it to run each time the machine was turned on. |
| T1069.002 Domain Groups |
GroupMustang Panda | Mustang Panda has leveraged AdFind to enumerate domain groups. |
| T1072 Software Deployment Tools |
GroupMustang Panda | Mustang Panda has leveraged legitimate software tools such as AntiVirus Agents, Security Services, and App Development tools to execute scripts and to side-load dlls. |
| T1083 File and Directory Discovery |
GroupMustang Panda | Mustang Panda has searched the entire target system for DOC, DOCX, PPT, PPTX, XLS, XLSX, and PDF files. |
| T1087.002 Domain Account |
GroupMustang Panda | Mustang Panda has utilized AdFind to identify domain users. |
| T1105 Ingress Tool Transfer |
MalwareTONESHELL | TONESHELL has the ability to download additional files to the victim device. |
| T1113 Screen Capture |
MalwareTONESHELL | TONESHELL has conducted screen capturing. |
| T1505.003 Web Shell |
GroupMustang Panda | Mustang Panda has used China Chopper web shells to maintain access to victims’ environments. |
| T1543.003 Windows Service |
MalwareTONESHELL | TONESHELL has created a malicious service DISMsrv to maintain persistence. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareTONESHELL | TONESHELL has added Registry Run keys to achieve persistence. |
| T1559 Inter-Process Communication |
MalwareTONESHELL | TONESHELL has facilitated inter-process communication between DLL components via the use of pipes. TONESHELL has also created a reverse shell using two anonymous pipes to write data to stdin and read data from stdout and stderr. |
| T1560.001 Archive via Utility |
MalwareTONESHELL | TONESHELL used WinRAR rar.exe to archive files for exfiltration. TONESHELL has also utilized a unique 13-character password consisting of upper lower case and digits to protect RAR archives. |
| T1560.001 Archive via Utility |
GroupMustang Panda | Mustang Panda has used RAR to create password-protected archives of collected documents prior to exfiltration. Mustang Panda has used WinRAR “Rar.exe” to archive stolen files before exfiltration. Mustang Panda has also used TONESHELL and post-exploitation tools such as RemCom and Impacket to execute WinRAR `rar.exe` to archive files for exfiltration. |
| T1567.002 Exfiltration to Cloud Storage |
GroupMustang Panda | Mustang Panda has also exfiltrated archived files to cloud services such as Dropbox using `curl`. |
| T1574.001 DLL |
MalwareTONESHELL | TONESHELL has abused legitimate executables to side-load malicious DLLs. TONESHELL has also been loaded via DLL side-loading, using legitimate, signed executables to include: FastVD.exe, Bandizip.exe and gpgconf.exe. 2022 November_TrendMicro_Earth Preta_Toneshell_PubloadATTACKIQ MUSTANG PANDA TONESHELL March 2023CSIRT CTI MUSTANG PANDA PUBLOAD TONESHELL JAN 2024Palo Alto Unit42 STATELY TAURUS TONESHELL September 2023Trend Micro Mustang Panda Earth Preta TONESHELL June 2023Trend Micro Mustang Panda Earth Preta Toneshell February 2025Zscaler |
| T1574.001 DLL |
GroupMustang Panda | Mustang Panda has used a legitimately signed executable to execute a malicious payload within a DLL file. Mustang Panda has abused legitimate executables to side-load malicious DLLs. 2022 November_TrendMicro_Earth Preta_Toneshell_Pubload2025_IBM_PUBLOAD_TONESHELL_HIUPAN_CLAIMLOADER_MUSTANG PANDAAnomali MUSTANG PANDA October 2019BroadcomCSIRT CTI MUSTANG PANDA PUBLOAD TONESHELL JAN 2024Cisco Talos MUSTANG PANDA PLUGX PUBLOAD MAY 2022EclecticIQ Mustang Panda PlugXEset PlugX Korplug Mustang Panda March 2022Google Threat Intelligence Group MUSTANG PANDA PLUGX August 2025IBM MUSTANG PANDA PUBLOAD CLAIMLOADER JUNE 2025Lab52 MUSTANG PANDA PUBLOAD MAY 2023Palo Alto Unit42 STATELY TAURUS TONESHELL September 2023Proofpoint TA416 November 2020Recorded Future REDDELTA July 2020Sophos PlugX September 2022Trend Micro Mustang Panda Earth Preta Toneshell February 2025Unit42 Bookworm Nov2015ZscalerZscaler PAKLOG CorkLog SplatCloak Splatdropper April 2025 |
| T1588.002 Tool |
GroupMustang Panda | Mustang Panda has obtained and leveraged publicly-available tools for intrusion activities. |
| T1654 Log Enumeration |
GroupMustang Panda | Mustang Panda has used Wevtutil to gather Windows Security Event Logs. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.