T1027.012 LNK Icon Smuggling |
MalwareTONESHELL |
TONESHELL has been initiated using LNK files that were programmed to display a PDF icon to entice the victim to click on the file to execute an office.exe binary. |
T1027.012 LNK Icon Smuggling |
GroupMustang Panda |
Mustang Panda has utilized LNK files to hide malicious scripts for execution. Mustang Panda has also leveraged LNK files that were programmed to display a PDF icon to entice the victim to click on the file to execute an office.exe binary. |
T1033 System Owner/User Discovery |
MalwarePUBLOAD |
PUBLOAD has obtained the username from an infected host. |
T1071.001 Web Protocols |
MalwareTONESHELL |
TONESHELL has utilized HTTP for a C2 protocol through HTTP POST. TONESHELL has also utilized HTTPS for C2. |
T1071.001 Web Protocols |
MalwarePUBLOAD |
PUBLOAD has communicated via `curl` over HTTP to identify device IP data. PUBLOAD has also utilized HTTP for a command-and-control protocol through HTTP POST. PUBLOAD has also leveraged HTTPS for C2. |
T1204.002 Malicious File |
GroupMustang Panda |
Mustang Panda has sent malicious files requiring direct victim interaction to execute. Mustang Panda has also leveraged executable files that display decoy documents to the victim to provide a resemblance of legitimacy with customized themes related to the victim. |
T1205 Traffic Signaling |
MalwarePUBLOAD |
PUBLOAD has utilized a magic value in C2 communications and only executes in memory when response packets match specific values of 17 03 03. PUBLOAD has also used magic bytes consisting of 46 77 4d. |
T1205 Traffic Signaling |
GroupMustang Panda |
Mustang Panda has utilized a magic value in C2 communications and only executes in memory when response packets match specific values of “17 03 03” or “46 77 4d”. |
T1547.001 Registry Run Keys / Startup Folder |
MalwarePUBLOAD |
PUBLOAD has added Registry Run keys to achieve persistence using `HKCU\Software\Microsoft\Windows\CurrentVersion\Run`. |
T1553.002 Code Signing |
GroupMustang Panda |
Mustang Panda has used valid legitimate digital signatures and certificates to evade detection. |
T1553.002 Code Signing |
MalwarePUBLOAD |
PUBLOAD has used valid legitimate digital signatures and certificates to evade detection. |
T1553.002 Code Signing |
MalwareTONESHELL |
TONESHELL has used valid legitimate digital signatures and certificates to evade detection. |
T1566.001 Spearphishing Attachment |
GroupMustang Panda |
Mustang Panda has used spearphishing attachments to deliver initial access payloads. Mustang Panda has also delivered archive files such as RAR and ZIP files containing legitimate EXEs and malicious DLLs. |
T1573.001 Symmetric Cryptography |
MalwarePUBLOAD |
PUBLOAD has used RC4 encryption in C2 communications. |
T1574.001 DLL |
MalwareTONESHELL |
TONESHELL has abused legitimate executables to side-load malicious DLLs. TONESHELL has also been loaded via DLL side-loading, using legitimate, signed executables to include: FastVD.exe, Bandizip.exe and gpgconf.exe. |
T1574.001 DLL |
GroupMustang Panda |
Mustang Panda has used a legitimately signed executable to execute a malicious payload within a DLL file. Mustang Panda has abused legitimate executables to side-load malicious DLLs. |
T1574.001 DLL |
MalwarePUBLOAD |
PUBLOAD has abused legitimate executables to side-load malicious DLLs. |
T1583.001 Domains |
GroupMustang Panda |
Mustang Panda has acquired C2 domains prior to operations. |
T1614.001 System Language Discovery |
MalwarePUBLOAD |
PUBLOAD has checked supported languages on the compromised system. |