Threat Advisory

Mustang Panda APT Targets Vietnam with Fake Tax and Education Documents

Threat: Malware
Threat Actor Name: Mustang Panda
Threat Actor Type: State-Sponsored
Targeted Region: U.S., Europe, Mongolia, Myanmar, Pakistan & Vietnam
Alias: G0129, Mustang Panda, Temp.Hex, Tantalum, HoneyMyte, PKPLUG /Stately Taurus, TA416, Bronze President, Earth Preta, Camaro Dragon, UAC-0084, Red Lich
Threat Actor Region: China
Targeted Sector: Government & Defense, Education, Finance & Banking
Criticality: High
[subscribe_to_unlock_form]

EXECUTIVE SUMMARY

Mustang Panda, a Chinese-affiliated APT group, has been observed conducting cyber espionage campaigns targeting a wide range of entities, including government organizations, nonprofits, and NGOs across the U.S., Europe, Mongolia, Myanmar, Pakistan, Vietnam, and other regions. Activities of this group have shown a focus on Vietnamese entities, leveraging lures related to tax compliance and the education sector to infiltrate systems.[/subscribe_to_unlock_form]

EXECUTIVE SUMMARY

Mustang Panda, a Chinese-affiliated APT group, has been observed conducting cyber espionage campaigns targeting a wide range of entities, including government organizations, nonprofits, and NGOs across the U.S., Europe, Mongolia, Myanmar, Pakistan, Vietnam, and other regions. Activities of this group have shown a focus on Vietnamese entities, leveraging lures related to tax compliance and the education sector to infiltrate systems.[emaillocker id="1283"]

The campaigns utilize multi-stage attacks beginning with spam emails containing ZIP or RAR files, which include malicious Windows shortcut (LNK) files disguised as legitimate documents. Upon execution, these LNK files employ legitimate tools such as forfiles.exe and mshta to execute malicious scripts hosted on remote servers. The process involves using PowerShell, VBScript, and batch files to further the attack, ultimately loading malicious DLLs via rundll32 and DLL sideloading techniques. These DLLs execute shellcode that connects to a Command and Control (C&C) server for additional malicious activities. The attackers have embedded partial lure documents within the LNK files to evade detection and increase file size, further complicating the identification of malicious activity.

The Mustang Panda campaigns highlight a threat landscape with evolving techniques such as spearphishing, DLL sideloading, and PowerShell scripting to infiltrate and maintain persistence in targeted systems. By leveraging legitimate tools and embedding lure documents, the attackers effectively evade detection and execute their espionage operations. These campaigns, utilizing themes of tax compliance and education, suggest a focus on exploiting entities involved in financial and educational activities, aiming to compromise sensitive information and maintain long-term access to targeted networks.

THREAT PROFILE:

Tactic Technique Id Technique
Execution T1059 Command and Scripting Interpreter
T1204 User Execution
Persistence  T1547 Boot or Logon Autostart Execution
Defense Evasion T1036 Masquerading
T1027 Obfuscated Files or Information
Discovery T1082 System Information Discovery
T1087 Account Discovery
 Collection T1005 Data from Local System
Exfiltration T1041 Exfiltration Over C2 Channel

REFERENCES:

The following reports contain further technical details:

https://cyble.com/blog/vietnamese-entities-targeted-by-china-linked-mustang-panda-in-cyber-espionage/

[/emaillocker]
crossmenu