EXECUTIVE SUMMARY
Mustang Panda, a Chinese-affiliated APT group, has been observed conducting cyber espionage campaigns targeting a wide range of entities, including government organizations, nonprofits, and NGOs across the U.S., Europe, Mongolia, Myanmar, Pakistan, Vietnam, and other regions. Activities of this group have shown a focus on Vietnamese entities, leveraging lures related to tax compliance and the education sector to infiltrate systems.[/subscribe_to_unlock_form]
EXECUTIVE SUMMARY
Mustang Panda, a Chinese-affiliated APT group, has been observed conducting cyber espionage campaigns targeting a wide range of entities, including government organizations, nonprofits, and NGOs across the U.S., Europe, Mongolia, Myanmar, Pakistan, Vietnam, and other regions. Activities of this group have shown a focus on Vietnamese entities, leveraging lures related to tax compliance and the education sector to infiltrate systems.[emaillocker id="1283"]
The campaigns utilize multi-stage attacks beginning with spam emails containing ZIP or RAR files, which include malicious Windows shortcut (LNK) files disguised as legitimate documents. Upon execution, these LNK files employ legitimate tools such as forfiles.exe and mshta to execute malicious scripts hosted on remote servers. The process involves using PowerShell, VBScript, and batch files to further the attack, ultimately loading malicious DLLs via rundll32 and DLL sideloading techniques. These DLLs execute shellcode that connects to a Command and Control (C&C) server for additional malicious activities. The attackers have embedded partial lure documents within the LNK files to evade detection and increase file size, further complicating the identification of malicious activity.
The Mustang Panda campaigns highlight a threat landscape with evolving techniques such as spearphishing, DLL sideloading, and PowerShell scripting to infiltrate and maintain persistence in targeted systems. By leveraging legitimate tools and embedding lure documents, the attackers effectively evade detection and execute their espionage operations. These campaigns, utilizing themes of tax compliance and education, suggest a focus on exploiting entities involved in financial and educational activities, aiming to compromise sensitive information and maintain long-term access to targeted networks.
THREAT PROFILE:
| Tactic | Technique Id | Technique |
| Execution | T1059 | Command and Scripting Interpreter |
| T1204 | User Execution | |
| Persistence | T1547 | Boot or Logon Autostart Execution |
| Defense Evasion | T1036 | Masquerading |
| T1027 | Obfuscated Files or Information | |
| Discovery | T1082 | System Information Discovery |
| T1087 | Account Discovery | |
| Collection | T1005 | Data from Local System |
| Exfiltration | T1041 | Exfiltration Over C2 Channel |
REFERENCES:
The following reports contain further technical details:
[/emaillocker]