Patrick Whitsell. (2025, August 25). Deception in Depth: PRC-Nexus Espionage Campaign Hijacks Web Traffic to Target Diplomats. Retrieved September 9, 2025.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1027.007 Dynamic API Resolution |
MalwareCANONSTAGER | CANONSTAGER has utilized custom API hashing to obfuscate the Windows APIs being used. |
| T1036.005 Match Legitimate Resource Name or Location |
GroupMustang Panda | Mustang Panda has used names like `adobeupdate.dat` and `PotPlayerDB.dat` to disguise PlugX, and a file named `OneDrive.exe` to load a Cobalt Strike payload. Mustang Panda has also masqueraded legitimate browser plugin updates to include AdobePlugins.exe. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareSTATICPLUGIN | STATICPLUGIN has leveraged naming conventions that match legitimate services to include AdobePlugins.exe. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareCANONSTAGER | CANONSTAGER has leveraged naming conventions of its malicious DLL to match legitimate services to include cnmpaui.dll which matches the legitimate executable cnmpaui.exe that is aligned with a Canon Ink Jet Printer Assistant Tool. |
| T1036.008 Masquerade File Type |
MalwareSTATICPLUGIN | STATICPLUGIN has masqueraded as a BMP file to hide its true MSI file extension. |
| T1055.005 Thread Local Storage |
MalwareCANONSTAGER | CANONSTAGER uses the Thread Local Storage (TLS) array data structure to store function addresses resolved by its custom API hashing algorithm. The function addresses are later called throughout the binary from offsets into the TLS array. |
| T1059.003 Windows Command Shell |
MalwarePlugX | PlugX allows actors to spawn a reverse shell on a victim. |
| T1071.001 Web Protocols |
MalwarePlugX | PlugX can be configured to use HTTP for command and control. PlugX has also used HTTPS for C2. |
| T1105 Ingress Tool Transfer |
MalwarePlugX | PlugX has a module to download and execute files on the compromised machine. |
| T1106 Native API |
MalwareCANONSTAGER | CANONSTAGER has leveraged Native API calls to execute code within the victim’s system including `GetCurrentDirectoryW`, `RegisterClassW` and `CreateWindowExW`. CANONSTAGER also created a new overlapped window that initiates callback functions to a windows procedure that processes Windows messages until a designated message type of 0x0018 WM_SHOWWINDOW is observed which then initiates the deployment of a subsequent malicious payload. |
| T1106 Native API |
GroupMustang Panda | Mustang Panda has used various Windows API calls during execution and defense evasion. 2022 November_TrendMicro_Earth Preta_Toneshell_Pubload2025_IBM_PUBLOAD_TONESHELL_HIUPAN_CLAIMLOADER_MUSTANG PANDABroadcomEset PlugX Korplug Mustang Panda March 2022Google Threat Intelligence Group MUSTANG PANDA PLUGX August 2025IBM MUSTANG PANDA PUBLOAD CLAIMLOADER JUNE 2025Lab52 MUSTANG PANDA PUBLOAD MAY 2023Palo Alto Networks, Unit 42Sophos Mustang Panda PLUGXTrend Micro Mustang Panda Earth Preta Toneshell February 2025ZscalerZscaler PAKLOG CorkLog SplatCloak Splatdropper April 2025 |
| T1140 Deobfuscate/Decode Files or Information |
GroupMustang Panda | Mustang Panda has the ability to decrypt its payload prior to execution. Mustang Panda has also utilized RC4 encryption for malicious payloads. |
| T1204.001 Malicious Link |
GroupMustang Panda | Mustang Panda has sent malicious links including links directing victims to a Google Drive folder. Mustang Panda has also utilized webpages with Javascript code that downloads malicious payloads to the victim device. 2022 November_TrendMicro_Earth Preta_Toneshell_Pubload2025_IBM_PUBLOAD_TONESHELL_HIUPAN_CLAIMLOADER_MUSTANG PANDACrowdstrike MUSTANG PANDA June 2018Google Threat Intelligence Group MUSTANG PANDA PLUGX August 2025IBM MUSTANG PANDA PUBLOAD CLAIMLOADER JUNE 2025McAfee Dianxun March 2021Proofpoint TA416 Europe March 2022 |
| T1204.002 Malicious File |
MalwareSTATICPLUGIN | STATICPLUGIN has required user execution to load subsequent malicious payloads. |
| T1553.002 Code Signing |
GroupMustang Panda | Mustang Panda has used valid legitimate digital signatures and certificates to evade detection. |
| T1553.002 Code Signing |
MalwareSTATICPLUGIN | STATICPLUGIN has been signed with a valid Certificate Authority(CA) to circumvent endpoint defenses. |
| T1557 Adversary-in-the-Middle |
GroupMustang Panda | Mustang Panda leveraged a captive portal hijack that redirected the victim to a webpage that prompted the victim to download a malicious payload. |
| T1559.001 Component Object Model |
MalwareSTATICPLUGIN | STATICPLUGIN has utilized Windows COM Installer Object to download an MSI package containing files masqueraded as a BMP file. |
| T1564.003 Hidden Window |
MalwareCANONSTAGER | CANONSTAGER has created a new window with a height and width of zero to remain hidden on the screen. |
| T1574.001 DLL |
GroupMustang Panda | Mustang Panda has used a legitimately signed executable to execute a malicious payload within a DLL file. Mustang Panda has abused legitimate executables to side-load malicious DLLs. 2022 November_TrendMicro_Earth Preta_Toneshell_Pubload2025_IBM_PUBLOAD_TONESHELL_HIUPAN_CLAIMLOADER_MUSTANG PANDAAnomali MUSTANG PANDA October 2019BroadcomCSIRT CTI MUSTANG PANDA PUBLOAD TONESHELL JAN 2024Cisco Talos MUSTANG PANDA PLUGX PUBLOAD MAY 2022EclecticIQ Mustang Panda PlugXEset PlugX Korplug Mustang Panda March 2022Google Threat Intelligence Group MUSTANG PANDA PLUGX August 2025IBM MUSTANG PANDA PUBLOAD CLAIMLOADER JUNE 2025Lab52 MUSTANG PANDA PUBLOAD MAY 2023Palo Alto Unit42 STATELY TAURUS TONESHELL September 2023Proofpoint TA416 November 2020Recorded Future REDDELTA July 2020Sophos PlugX September 2022Trend Micro Mustang Panda Earth Preta Toneshell February 2025Unit42 Bookworm Nov2015ZscalerZscaler PAKLOG CorkLog SplatCloak Splatdropper April 2025 |
| T1574.001 DLL |
MalwareCANONSTAGER | CANONSTAGER has abused legitimate executables to side-load malicious DLLs. |
| T1583.001 Domains |
GroupMustang Panda | Mustang Panda has acquired C2 domains prior to operations. CSIRT CTI MUSTANG PANDA PUBLOAD TONESHELL JAN 2024Google Threat Intelligence Group MUSTANG PANDA PLUGX August 2025Lab52 MUSTANG PANDA PUBLOAD MAY 2023McAfee Dianxun March 2021Palo Alto Networks, Unit 42Recorded Future REDDELTA July 2020Secureworks BRONZE PRESIDENT December 2019Trend Micro Mustang Panda Earth Preta Toneshell February 2025Unit42 Bookworm Nov2015 |
| T1588.004 Digital Certificates |
GroupMustang Panda | Mustang Panda has obtained SSL certificates for their C2 domains. |
| T1620 Reflective Code Loading |
MalwarePlugX | PlugX has loaded its payload into memory. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.