T1001.003 Protocol or Service Impersonation |
MalwarePUBLOAD |
PUBLOAD has modified HTTP POST requests to resemble legitimate communications. PUBLOAD used FakeTLS headers in network packets to impersonate various versions of TLS protocols to blend in with legitimate network traffic. PUBLOAD has utilized FakeTLS headers with the bytes 17 03 03. |
T1027.015 Compression |
MalwarePUBLOAD |
PUBLOAD has been delivered as compressed files within ZIP files to victims. |
T1053.005 Scheduled Task |
MalwarePUBLOAD |
PUBLOAD has created scheduled tasks to maintain persistence with the command `schtasks.exe /F /Create /TN Microsoft_Licensing /sc minute /MO 1 /TR C:\\Users\\Public\\Libraries\...` |
T1071.001 Web Protocols |
MalwarePUBLOAD |
PUBLOAD has communicated via `curl` over HTTP to identify device IP data. PUBLOAD has also utilized HTTP for a command-and-control protocol through HTTP POST. PUBLOAD has also leveraged HTTPS for C2. |
T1105 Ingress Tool Transfer |
MalwarePUBLOAD |
PUBLOAD has acted as a stager that can download the next-stage payload from its C2 server. PUBLOAD has also delivered FDMTP as a secondary control tool and PTSOCKET for exfiltration to some infected systems. |
T1106 Native API |
GroupMustang Panda |
Mustang Panda has used various Windows API calls during execution and defense evasion. |
T1106 Native API |
MalwarePUBLOAD |
PUBLOAD has used various Windows API calls during execution, when establishing persistence and defense evasion. PUBLOAD stager leveraged Windows API functions with callback including `GrayStringW`, `EnumDateFormatsA`, and `LineDDA` to bypass anti-virus monitoring. PUBLOAD has also utilized other native windows API functions with callback functions such as `EnumChildWindows` and `EnumSystemLanguageGroupsA`. |
T1140 Deobfuscate/Decode Files or Information |
GroupMustang Panda |
Mustang Panda has the ability to decrypt its payload prior to execution. Mustang Panda has also utilized RC4 encryption for malicious payloads. |
T1140 Deobfuscate/Decode Files or Information |
MalwarePUBLOAD |
PUBLOAD has decoded its payload prior to execution. |
T1204.002 Malicious File |
GroupMustang Panda |
Mustang Panda has sent malicious files requiring direct victim interaction to execute. Mustang Panda has also leveraged executable files that display decoy documents to the victim to provide a resemblance of legitimacy with customized themes related to the victim. |
T1547.001 Registry Run Keys / Startup Folder |
MalwarePUBLOAD |
PUBLOAD has added Registry Run keys to achieve persistence using `HKCU\Software\Microsoft\Windows\CurrentVersion\Run`. |
T1553.002 Code Signing |
GroupMustang Panda |
Mustang Panda has used valid legitimate digital signatures and certificates to evade detection. |
T1566.001 Spearphishing Attachment |
GroupMustang Panda |
Mustang Panda has used spearphishing attachments to deliver initial access payloads. Mustang Panda has also delivered archive files such as RAR and ZIP files containing legitimate EXEs and malicious DLLs. |
T1574.001 DLL |
MalwarePUBLOAD |
PUBLOAD has abused legitimate executables to side-load malicious DLLs. |
T1574.001 DLL |
GroupMustang Panda |
Mustang Panda has used a legitimately signed executable to execute a malicious payload within a DLL file. Mustang Panda has abused legitimate executables to side-load malicious DLLs. |
T1583.001 Domains |
GroupMustang Panda |
Mustang Panda has acquired C2 domains prior to operations. |