ATT&CKSoftwareSTATICPLUGIN

STATICPLUGIN

S1238

Malware.View on attack.mitre.org

About this malware

STATICPLUGIN is a downloader known to be leveraged by Mustang Panda and was first observed utilized in 2025. STATICPLUGIN has utilized a valid certificate in order to bypass endpoint security protections. STATICPLUGIN masqueraded as legitimate software installer by using a custom TForm. STATICPLUGIN has been leveraged to deploy a loader that facilitates follow on malware.

Techniques used5

Procedure examples5

TechniqueProcedure example
T1036.005
Match Legitimate Resource Name or Location

STATICPLUGIN has leveraged naming conventions that match legitimate services to include AdobePlugins.exe.

T1036.008
Masquerade File Type

STATICPLUGIN has masqueraded as a BMP file to hide its true MSI file extension.

T1204.002
Malicious File

STATICPLUGIN has required user execution to load subsequent malicious payloads.

T1553.002
Code Signing

STATICPLUGIN has been signed with a valid Certificate Authority(CA) to circumvent endpoint defenses.

T1559.001
Component Object Model

STATICPLUGIN has utilized Windows COM Installer Object to download an MSI package containing files masqueraded as a BMP file.

Groups that use it1

Campaigns0

None recorded.

References1

  1. Google Threat Intelligence Group MUSTANG PANDA PLUGX August 2025 Open source
    Patrick Whitsell. (2025, August 25). Deception in Depth: PRC-Nexus Espionage Campaign Hijacks Web Traffic to Target Diplomats. Retrieved September 9, 2025.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.