ATT&CKReferencesTrend Micro Mustang Panda Earth Preta Toneshell February 2025

Trend Micro Mustang Panda Earth Preta Toneshell February 2025

Nathaniel Morales, Nick Dai. (2025, February 18). Earth Preta Mixes Legitimate and Malicious Components to Sidestep Detection. Retrieved September 10, 2025.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples17

TechniqueUsed byProcedure example
T1057
Process Discovery
MalwareTONESHELL

TONESHELL has checked the process name and process path to ensure it matches the expected one prior to triggering a custom exception handler. TONESHELL has also searched for running antivirus processes to include ESET’s antivirus associated executables ekrn.exe and egui.exe.

T1072
Software Deployment Tools
GroupMustang Panda

Mustang Panda has leveraged legitimate software tools such as AntiVirus Agents, Security Services, and App Development tools to execute scripts and to side-load dlls.

T1082
System Information Discovery
MalwareTONESHELL

TONESHELL has the ability to retrieve the name of the infected machine.

T1106
Native API
GroupMustang Panda

Mustang Panda has used various Windows API calls during execution and defense evasion.

T1106
Native API
MalwareTONESHELL

TONESHELL has utilized Native Windows API functions such as `WriteProcessMemory` and `CreateRemoteThreadEx`. TONESHELL has also utilized Windows API functions for creating seed values including `CoCreateGuid` and `GetTickCount`. TONESHELL has leveraged the legitimate API function `EnumSystemLocalesA` to run its shellcode through the callback function.

T1140
Deobfuscate/Decode Files or Information
MalwareTONESHELL

TONESHELL has decoded its payload prior to execution.

T1204.002
Malicious File
GroupMustang Panda

Mustang Panda has sent malicious files requiring direct victim interaction to execute. Mustang Panda has also leveraged executable files that display decoy documents to the victim to provide a resemblance of legitimacy with customized themes related to the victim.

T1205
Traffic Signaling
MalwareTONESHELL

TONESHELL has utilized a magic value in C2 communications and only executes in memory when response packets match specific values.

T1218.010
Regsvr32
MalwareTONESHELL

TONESHELL has used regsvr32.exe to execute the windows `DLLRegisterServer` function.

T1218.013
Mavinject
MalwareTONESHELL

TONESHELL has injected its malicious payload into a running process through Windows utility Microsoft Application Virtualization Injector `MAVInject.exe`.

T1480
Execution Guardrails
MalwareTONESHELL

TONESHELL has an exception handler that executes when ESET antivirus applications `ekrn.exe` and `egui.exe` are not found and directly injects its code into waitfor.exe using Native Windows API including `WriteProcessMemory` and `CreateRemoteThreadEx`.

T1480.001
Environmental Keying
MalwareTONESHELL

TONESHELL has generated unique GUIDs to identify victim devices. TONESHELL has leveraged environmental keying in payload delivery using the victim computer name and other configuration values. TONESHELL has also tracked IDs associated with reverse shell subprocesses to manage interactions and terminations from C2.

T1518.001
Security Software Discovery
MalwareTONESHELL

TONESHELL has checked for the presence of ESET antivirus applications `ekrn.exe` and `egui.exe`.

T1574.001
DLL
GroupMustang Panda

Mustang Panda has used a legitimately signed executable to execute a malicious payload within a DLL file. Mustang Panda has abused legitimate executables to side-load malicious DLLs.

T1574.001
DLL
MalwareTONESHELL

TONESHELL has abused legitimate executables to side-load malicious DLLs. TONESHELL has also been loaded via DLL side-loading, using legitimate, signed executables to include: FastVD.exe, Bandizip.exe and gpgconf.exe.

T1574.005
Executable Installer File Permissions Weakness
GroupMustang Panda

Mustang Panda has leveraged legitimate software installer executables such as Setup Factory “IRSetup.exe” to drop and execute their payload.

T1583.001
Domains
GroupMustang Panda

Mustang Panda has acquired C2 domains prior to operations.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.