ATT&CKReferencesGoogle Threat Intelligence Group MUSTANG PANDA PLUGX August 2025

Google Threat Intelligence Group MUSTANG PANDA PLUGX August 2025

Patrick Whitsell. (2025, August 25). Deception in Depth: PRC-Nexus Espionage Campaign Hijacks Web Traffic to Target Diplomats. Retrieved September 9, 2025.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software2

Campaigns0

None recorded.

Procedure examples24

TechniqueUsed byProcedure example
T1027.007
Dynamic API Resolution
MalwareCANONSTAGER

CANONSTAGER has utilized custom API hashing to obfuscate the Windows APIs being used.

T1036.005
Match Legitimate Resource Name or Location
GroupMustang Panda

Mustang Panda has used names like `adobeupdate.dat` and `PotPlayerDB.dat` to disguise PlugX, and a file named `OneDrive.exe` to load a Cobalt Strike payload. Mustang Panda has also masqueraded legitimate browser plugin updates to include AdobePlugins.exe.

T1036.005
Match Legitimate Resource Name or Location
MalwareSTATICPLUGIN

STATICPLUGIN has leveraged naming conventions that match legitimate services to include AdobePlugins.exe.

T1036.005
Match Legitimate Resource Name or Location
MalwareCANONSTAGER

CANONSTAGER has leveraged naming conventions of its malicious DLL to match legitimate services to include cnmpaui.dll which matches the legitimate executable cnmpaui.exe that is aligned with a Canon Ink Jet Printer Assistant Tool.

T1036.008
Masquerade File Type
MalwareSTATICPLUGIN

STATICPLUGIN has masqueraded as a BMP file to hide its true MSI file extension.

T1055.005
Thread Local Storage
MalwareCANONSTAGER

CANONSTAGER uses the Thread Local Storage (TLS) array data structure to store function addresses resolved by its custom API hashing algorithm. The function addresses are later called throughout the binary from offsets into the TLS array.

T1059.003
Windows Command Shell
MalwarePlugX

PlugX allows actors to spawn a reverse shell on a victim.

T1071.001
Web Protocols
MalwarePlugX

PlugX can be configured to use HTTP for command and control. PlugX has also used HTTPS for C2.

T1105
Ingress Tool Transfer
MalwarePlugX

PlugX has a module to download and execute files on the compromised machine.

T1106
Native API
MalwareCANONSTAGER

CANONSTAGER has leveraged Native API calls to execute code within the victim’s system including `GetCurrentDirectoryW`, `RegisterClassW` and `CreateWindowExW`. CANONSTAGER also created a new overlapped window that initiates callback functions to a windows procedure that processes Windows messages until a designated message type of 0x0018 WM_SHOWWINDOW is observed which then initiates the deployment of a subsequent malicious payload.

T1106
Native API
GroupMustang Panda

Mustang Panda has used various Windows API calls during execution and defense evasion.

T1140
Deobfuscate/Decode Files or Information
GroupMustang Panda

Mustang Panda has the ability to decrypt its payload prior to execution. Mustang Panda has also utilized RC4 encryption for malicious payloads.

T1204.001
Malicious Link
GroupMustang Panda

Mustang Panda has sent malicious links including links directing victims to a Google Drive folder. Mustang Panda has also utilized webpages with Javascript code that downloads malicious payloads to the victim device.

T1204.002
Malicious File
MalwareSTATICPLUGIN

STATICPLUGIN has required user execution to load subsequent malicious payloads.

T1553.002
Code Signing
GroupMustang Panda

Mustang Panda has used valid legitimate digital signatures and certificates to evade detection.

T1553.002
Code Signing
MalwareSTATICPLUGIN

STATICPLUGIN has been signed with a valid Certificate Authority(CA) to circumvent endpoint defenses.

T1557
Adversary-in-the-Middle
GroupMustang Panda

Mustang Panda leveraged a captive portal hijack that redirected the victim to a webpage that prompted the victim to download a malicious payload.

T1559.001
Component Object Model
MalwareSTATICPLUGIN

STATICPLUGIN has utilized Windows COM Installer Object to download an MSI package containing files masqueraded as a BMP file.

T1564.003
Hidden Window
MalwareCANONSTAGER

CANONSTAGER has created a new window with a height and width of zero to remain hidden on the screen.

T1574.001
DLL
GroupMustang Panda

Mustang Panda has used a legitimately signed executable to execute a malicious payload within a DLL file. Mustang Panda has abused legitimate executables to side-load malicious DLLs.

T1574.001
DLL
MalwareCANONSTAGER

CANONSTAGER has abused legitimate executables to side-load malicious DLLs.

T1583.001
Domains
GroupMustang Panda

Mustang Panda has acquired C2 domains prior to operations.

T1588.004
Digital Certificates
GroupMustang Panda

Mustang Panda has obtained SSL certificates for their C2 domains.

T1620
Reflective Code Loading
MalwarePlugX

PlugX has loaded its payload into memory.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.