ATT&CKSoftwareCANONSTAGER

CANONSTAGER

S1237

Malware.View on attack.mitre.org

About this malware

CANONSTAGER is a loader known to be leveraged by Mustang Panda and was first observed utilized in 2025. Mustang Panda utilizes DLL side-loading to execute within the victim environment prior to delivering a follow-on malicious encrypted payload. CANONSTAGER leverages Thread Local Storage (TLS) and Native Windows APIs within the victim environment to elude detections. CANONSTAGER also hides its code utilizing window procedures and message queues.

Techniques used6

Procedure examples6

TechniqueProcedure example
T1027.007
Dynamic API Resolution

CANONSTAGER has utilized custom API hashing to obfuscate the Windows APIs being used.

T1036.005
Match Legitimate Resource Name or Location

CANONSTAGER has leveraged naming conventions of its malicious DLL to match legitimate services to include cnmpaui.dll which matches the legitimate executable cnmpaui.exe that is aligned with a Canon Ink Jet Printer Assistant Tool.

T1055.005
Thread Local Storage

CANONSTAGER uses the Thread Local Storage (TLS) array data structure to store function addresses resolved by its custom API hashing algorithm. The function addresses are later called throughout the binary from offsets into the TLS array.

T1106
Native API

CANONSTAGER has leveraged Native API calls to execute code within the victim’s system including `GetCurrentDirectoryW`, `RegisterClassW` and `CreateWindowExW`. CANONSTAGER also created a new overlapped window that initiates callback functions to a windows procedure that processes Windows messages until a designated message type of 0x0018 WM_SHOWWINDOW is observed which then initiates the deployment of a subsequent malicious payload.

T1564.003
Hidden Window

CANONSTAGER has created a new window with a height and width of zero to remain hidden on the screen.

T1574.001
DLL

CANONSTAGER has abused legitimate executables to side-load malicious DLLs.

Groups that use it1

Campaigns0

None recorded.

References1

  1. Google Threat Intelligence Group MUSTANG PANDA PLUGX August 2025 Open source
    Patrick Whitsell. (2025, August 25). Deception in Depth: PRC-Nexus Espionage Campaign Hijacks Web Traffic to Target Diplomats. Retrieved September 9, 2025.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.