ATT&CKReferences2022 November_TrendMicro_Earth Preta_Toneshell_Pubload

2022 November_TrendMicro_Earth Preta_Toneshell_Pubload

Nick Dai, Vickie Su, Sunny Lu. (2022, November 18). Earth Preta Spear-Phishing Governments Worldwide. Retrieved August 4, 2025.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples38

TechniqueUsed byProcedure example
T1010
Application Window Discovery
MalwareTONESHELL

TONESHELL has used `GetForegroundWindow` to detect virtualization or sandboxes by calling the API twice and comparing each window handle.

T1027
Obfuscated Files or Information
GroupMustang Panda

Mustang Panda has delivered initial payloads hidden using archives and encoding measures. Mustang Panda has also utilized opaque predicates in payloads to hinder analysis.

T1033
System Owner/User Discovery
MalwarePUBLOAD

PUBLOAD has obtained the username from an infected host.

T1033
System Owner/User Discovery
MalwareTONESHELL

TONESHELL has obtained the username from an infected host.

T1036.005
Match Legitimate Resource Name or Location
MalwareTONESHELL

TONESHELL has renamed malicious files to mimic legitimate file names and file extensions. TONESHELL has also masqueraded as legitimate file names to include LogMeIn.dll.

T1036.005
Match Legitimate Resource Name or Location
MalwarePUBLOAD

PUBLOAD has renamed malicious files to mimic legitimate file names such as adobe_wf.exe.

T1053.005
Scheduled Task
MalwarePUBLOAD

PUBLOAD has created scheduled tasks to maintain persistence with the command `schtasks.exe /F /Create /TN Microsoft_Licensing /sc minute /MO 1 /TR C:\\Users\\Public\\Libraries\...`

T1057
Process Discovery
GroupMustang Panda

Mustang Panda has used tasklist /v to determine active process information. Mustang Panda has also used TONESHELL malware to check the process name and process path to ensure it matches the expected one prior to triggering a custom exception handler.

T1057
Process Discovery
MalwarePUBLOAD

PUBLOAD has used `tasklist` to gather running processes on victim host. PUBLOAD has also leveraged the `OpenEventA` Windows API function to check whether the same process was already running.

T1057
Process Discovery
MalwareTONESHELL

TONESHELL has checked the process name and process path to ensure it matches the expected one prior to triggering a custom exception handler. TONESHELL has also searched for running antivirus processes to include ESET’s antivirus associated executables ekrn.exe and egui.exe.

T1071.001
Web Protocols
MalwareTONESHELL

TONESHELL has utilized HTTP for a C2 protocol through HTTP POST. TONESHELL has also utilized HTTPS for C2.

T1082
System Information Discovery
MalwarePUBLOAD

PUBLOAD has collected and sent system information including volume serial number, computer name, and system uptime to designated C2. PUBLOAD has also used several commands executed in sequence via `cmd` in a short interval to gather system information about the infected host including `systeminfo`. PUBLOAD has decrypted shellcode that collects the computer name.

T1095
Non-Application Layer Protocol
MalwareTONESHELL

TONESHELL has utilized TCP-based reverse shells.

T1105
Ingress Tool Transfer
MalwarePUBLOAD

PUBLOAD has acted as a stager that can download the next-stage payload from its C2 server. PUBLOAD has also delivered FDMTP as a secondary control tool and PTSOCKET for exfiltration to some infected systems.

T1106
Native API
MalwarePUBLOAD

PUBLOAD has used various Windows API calls during execution, when establishing persistence and defense evasion. PUBLOAD stager leveraged Windows API functions with callback including `GrayStringW`, `EnumDateFormatsA`, and `LineDDA` to bypass anti-virus monitoring. PUBLOAD has also utilized other native windows API functions with callback functions such as `EnumChildWindows` and `EnumSystemLanguageGroupsA`.

T1106
Native API
GroupMustang Panda

Mustang Panda has used various Windows API calls during execution and defense evasion.

T1132.002
Non-Standard Encoding
MalwareTONESHELL

TONESHELL has encoded a payload with a random 32-byte key using XOR. TONESHELL has also encoded payloads with a 256-byte key using XOR.

T1140
Deobfuscate/Decode Files or Information
MalwarePUBLOAD

PUBLOAD has decoded its payload prior to execution.

T1140
Deobfuscate/Decode Files or Information
MalwareTONESHELL

TONESHELL has decoded its payload prior to execution.

T1204.001
Malicious Link
GroupMustang Panda

Mustang Panda has sent malicious links including links directing victims to a Google Drive folder. Mustang Panda has also utilized webpages with Javascript code that downloads malicious payloads to the victim device.

T1204.002
Malicious File
GroupMustang Panda

Mustang Panda has sent malicious files requiring direct victim interaction to execute. Mustang Panda has also leveraged executable files that display decoy documents to the victim to provide a resemblance of legitimacy with customized themes related to the victim.

T1205
Traffic Signaling
MalwarePUBLOAD

PUBLOAD has utilized a magic value in C2 communications and only executes in memory when response packets match specific values of 17 03 03. PUBLOAD has also used magic bytes consisting of 46 77 4d.

T1205
Traffic Signaling
MalwareTONESHELL

TONESHELL has utilized a magic value in C2 communications and only executes in memory when response packets match specific values.

T1480.001
Environmental Keying
MalwareTONESHELL

TONESHELL has generated unique GUIDs to identify victim devices. TONESHELL has leveraged environmental keying in payload delivery using the victim computer name and other configuration values. TONESHELL has also tracked IDs associated with reverse shell subprocesses to manage interactions and terminations from C2.

T1497.002
User Activity Based Checks
MalwareTONESHELL

TONESHELL has leveraged `GetForegroundWindow` to detect virtualization or sandboxes by calling the API twice and comparing each window handle.

T1547.001
Registry Run Keys / Startup Folder
MalwarePUBLOAD

PUBLOAD has added Registry Run keys to achieve persistence using `HKCU\Software\Microsoft\Windows\CurrentVersion\Run`.

T1566.002
Spearphishing Link
GroupMustang Panda

Mustang Panda has delivered malicious links to their intended targets. Mustang Panda has distributed spear-phishing emails with embedded links that direct the victim to a malicious archive hosted on Google or Dropbox.

T1573.001
Symmetric Cryptography
MalwarePUBLOAD

PUBLOAD has used RC4 encryption in C2 communications.

T1573.001
Symmetric Cryptography
MalwareTONESHELL

TONESHELL has used RC4 encryption in C2 communications. TONESHELL variants used a randomly generated variable length (0x20 - 0x200 bytes) rolling XOR key to encrypt and decrypt network packets.

T1574.001
DLL
GroupMustang Panda

Mustang Panda has used a legitimately signed executable to execute a malicious payload within a DLL file. Mustang Panda has abused legitimate executables to side-load malicious DLLs.

T1574.001
DLL
MalwareTONESHELL

TONESHELL has abused legitimate executables to side-load malicious DLLs. TONESHELL has also been loaded via DLL side-loading, using legitimate, signed executables to include: FastVD.exe, Bandizip.exe and gpgconf.exe.

T1574.001
DLL
MalwarePUBLOAD

PUBLOAD has abused legitimate executables to side-load malicious DLLs.

T1583.006
Web Services
GroupMustang Panda

Mustang Panda has set up Dropbox and Google Drive to host malicious downloads.

T1585.002
Email Accounts
GroupMustang Panda

Mustang Panda has leveraged the legitimate email marketing service SMTP2Go for phishing campaigns. Mustang Panda has also created fake Google accounts to distribute malware via spear-phishing emails. Mustang Panda has also created accounts for spearphishing operations including the use of services such as Proton Mail.

T1586.002
Email Accounts
GroupMustang Panda

Mustang Panda has compromised legitimate email accounts to use in their spear-phishing operations.

T1622
Debugger Evasion
MalwareTONESHELL

TONESHELL has leveraged custom exception handlers to hide code flow and stop execution of a debugger.

T1622
Debugger Evasion
GroupMustang Panda

Mustang Panda has embedded debug strings with messages to distract analysts. Mustang Panda has also made calls to Windows API `CheckRemoteDebuggerPresent` and exits if it detects a debugger.

T1622
Debugger Evasion
MalwarePUBLOAD

PUBLOAD has embedded debug strings with messages to distract analysts. PUBLOAD has leveraged `OutputDebugStringW` and `OutputDebugStringA` functions.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.