T1027.007 Dynamic API Resolution |
MalwareCLAIMLOADER |
CLAIMLOADER has utilized XOR-encrypted API names and native APIs of `LdrLoadDll()` and `LderGetProcedureAddress()` to resolve imports dynamically. |
T1102 Web Service |
GroupMustang Panda |
Mustang Panda has used DropBox URLs to deliver variants of PlugX. Mustang Panda has also used Google Drive to host malicious downloads. |
T1105 Ingress Tool Transfer |
MalwarePUBLOAD |
PUBLOAD has acted as a stager that can download the next-stage payload from its C2 server. PUBLOAD has also delivered FDMTP as a secondary control tool and PTSOCKET for exfiltration to some infected systems. |
T1106 Native API |
MalwareCLAIMLOADER |
CLAIMLOADER has used various Windows API calls during execution, when establishing persistence and defense evasion. CLAIMLOADER has also leveraged the legitimate API functions to run its shellcode through the callback function, including `GetDC()` and `EnumFontsW()`. CLAIMLOADER established persistence by utilizing the API `SHSetValue()`. CLAIMLOADER has utilized APIs with callback functions such as `EnumpropsExW`, `EnumSystemLanguageGroupsA`, and `EnumCalendarInfoExW`. |
T1106 Native API |
GroupMustang Panda |
Mustang Panda has used various Windows API calls during execution and defense evasion. |
T1140 Deobfuscate/Decode Files or Information |
MalwareCLAIMLOADER |
CLAIMLOADER has decoded its payload prior to execution. |
T1204.001 Malicious Link |
GroupMustang Panda |
Mustang Panda has sent malicious links including links directing victims to a Google Drive folder. Mustang Panda has also utilized webpages with Javascript code that downloads malicious payloads to the victim device. |
T1204.002 Malicious File |
GroupMustang Panda |
Mustang Panda has sent malicious files requiring direct victim interaction to execute. Mustang Panda has also leveraged executable files that display decoy documents to the victim to provide a resemblance of legitimacy with customized themes related to the victim. |
T1205 Traffic Signaling |
MalwarePUBLOAD |
PUBLOAD has utilized a magic value in C2 communications and only executes in memory when response packets match specific values of 17 03 03. PUBLOAD has also used magic bytes consisting of 46 77 4d. |
T1480.002 Mutual Exclusion |
MalwareCLAIMLOADER |
CLAIMLOADER has created hardcoded mutex to ensure only a single instance of the malware is running. |
T1547.001 Registry Run Keys / Startup Folder |
MalwareCLAIMLOADER |
CLAIMLOADER has added Registry Run keys to achieve persistence using `HKCU\Software\Microsoft\Windows\CurrentVersion\Run`. |
T1566.001 Spearphishing Attachment |
GroupMustang Panda |
Mustang Panda has used spearphishing attachments to deliver initial access payloads. Mustang Panda has also delivered archive files such as RAR and ZIP files containing legitimate EXEs and malicious DLLs. |
T1566.002 Spearphishing Link |
GroupMustang Panda |
Mustang Panda has delivered malicious links to their intended targets. Mustang Panda has distributed spear-phishing emails with embedded links that direct the victim to a malicious archive hosted on Google or Dropbox. |
T1574.001 DLL |
MalwareCLAIMLOADER |
CLAIMLOADER has used a legitimately signed executable to execute a malicious payload within a DLL file. |
T1574.001 DLL |
GroupMustang Panda |
Mustang Panda has used a legitimately signed executable to execute a malicious payload within a DLL file. Mustang Panda has abused legitimate executables to side-load malicious DLLs. |
T1585.002 Email Accounts |
GroupMustang Panda |
Mustang Panda has leveraged the legitimate email marketing service SMTP2Go for phishing campaigns. Mustang Panda has also created fake Google accounts to distribute malware via spear-phishing emails. Mustang Panda has also created accounts for spearphishing operations including the use of services such as Proton Mail. |
T1593 Search Open Websites/Domains |
GroupMustang Panda |
Mustang Panda has used open-source research to identify information about victims to use in targeting to include creating weaponized phishing lures and attachments. |