Chinese ‘Mustang Panda’ Hackers Actively Targeting Governments Worldwide

Teilen:

A notorious advanced persistent threat actor known as Mustang Panda has been linked to a spate of spear-phishing attacks targeting government, education, and research sectors across the world.

The primary targets of the intrusions from May to October 2022 included counties in the Asia Pacific region such as Myanmar, Australia, the Philippines, Japan, and Taiwan, cybersecurity firm Trend Micro sagte in a Friday report.

Mustang Panda, also called Bronze President, Earth Preta, HoneyMyte, and Red Lich, is a China-based espionage actor believed to be active since at least July 2018. The group is known for its use of malware, such as China Chopper and PlugX to collect data from compromised environments.

Activities of the group chronicled by ESETGoogle, ProofpointCisco Talosund Secureworks this year have revealed the threat actor’s pattern of using PlugX (and its variant called Hodur) to infect a wide range of entities in Asia, Europe, the Middle East, and the Americas.

The latest findings from Trend Micro show that Mustang Panda continues to evolve its tactics in a strategy to evade detection and adopt infection routines that lead to the deployment of bespoke malware families like TONEINS, TONESHELL, and PUBLOAD.

“Earth Preta abused fake Google accounts to distribute the malware via spear-phishing emails, initially stored in an archive file (such as RAR/ZIP/JAR) and distributed through Google Drive links,” researchers Nick Dai, Vickie Su, and Sunny Lu said.

Initial access is facilitated through decoy documents that cover controversial geopolitical themes to entice the targeted organizations into downloading and triggering the malware.

In some cases, the phishing messages were sent from previously compromised email accounts belonging to specific entities, indicating the efforts undertaken by the Mustang Panda actor to increase the likelihood of the success of its campaigns.

The archive files, when opened, are designed to display a lure document to the victim, while stealthily loading the malware in the background through a method referred to as DLL side-loading.

The attack chains ultimately lead to the delivery of three malware families – PUBLOAD, TONEINS, and TONESHELL – which are capable of downloading next-stage payloads and flying under the radar.

TONESHELL, the main backdoor used in the attacks, is installed through TONEINS and is a shellcode loader, with an early version of the implant detected in September 2021, suggesting continued efforts on part of the threat actor to update its arsenal.

Bild4

“Earth Preta is a cyber espionage group known to develop their own loaders in combination with existing tools like PlugX and Cobalt Strike for compromise,” the researchers concluded.

“Once the group has infiltrated a targeted victim’s systems, the sensitive documents stolen can be abused as the entry vectors for the next wave of intrusions. This strategy largely broadens the affected scope in the region involved.”

https://thehackernews.com/2022/11/chinese-mustang-panda-hackers-actively.html

Kommentar verfassen

Deine E-Mail-Adresse wird nicht veröffentlicht. Erforderliche Felder sind mit * markiert

lade-bild
London, GB
12:04 am, Juli 12, 2025
Wetter-Symbol 22°C
L: 21° | H: 23°
klarer Himmel
Luftfeuchtigkeit: 66 %
Druck: 1018 mb
Wind: 6 mph ESE
Windböe: 0 mph
UV-Index: 0
Niederschlag: 0 mm
Wolken: 1%
Regen Chance: 0%
Sichtbarkeit: 10 km
Sonnenaufgang: 4:56 am
Sonnenuntergang: 9:15 pm
TäglichStündlich
Tägliche VorhersageStündliche Vorhersage
Today 10:00 pm
Wetter-Symbol
21° | 23°°C 0 mm 0% 10 mph 65 % 1018 mb 0 mm/h
Tomorrow 10:00 pm
Wetter-Symbol
17° | 29°°C 0 mm 0% 7 mph 66 % 1015 mb 0 mm/h
Mo. Juli 14 10:00 pm
Wetter-Symbol
19° | 28°°C 0 mm 0% 14 mph 71 % 1017 mb 0 mm/h
Di. Juli 15 10:00 pm
Wetter-Symbol
15° | 25°°C 0 mm 0% 13 mph 68 % 1020 mb 0 mm/h
Mi. Juli 16 10:00 pm
Wetter-Symbol
18° | 25°°C 1 mm 100% 13 mph 83 % 1019 mb 0 mm/h
Today 1:00 am
Wetter-Symbol
20° | 22°°C 0 mm 0% 3 mph 65 % 1018 mb 0 mm/h
Today 4:00 am
Wetter-Symbol
17° | 21°°C 0 mm 0% 4 mph 64 % 1018 mb 0 mm/h
Today 7:00 am
Wetter-Symbol
19° | 20°°C 0 mm 0% 5 mph 65 % 1018 mb 0 mm/h
Today 10:00 am
Wetter-Symbol
26° | 26°°C 0 mm 0% 6 mph 44 % 1017 mb 0 mm/h
Today 1:00 pm
Wetter-Symbol
29° | 29°°C 0 mm 0% 6 mph 32 % 1016 mb 0 mm/h
Today 4:00 pm
Wetter-Symbol
29° | 29°°C 0 mm 0% 10 mph 30 % 1014 mb 0 mm/h
Today 7:00 pm
Wetter-Symbol
25° | 25°°C 0 mm 0% 9 mph 41 % 1014 mb 0 mm/h
Today 10:00 pm
Wetter-Symbol
21° | 21°°C 0 mm 0% 6 mph 55 % 1015 mb 0 mm/h
Name Preis24H (%)
Bitcoin(BTC)
€100,621.43
1.33%
Ethereum(ETH)
€2,523.09
-0.79%
Fesseln(USDT)
€0.86
0.02%
XRP(XRP)
€2.30
5.86%
Solana(SOL)
€137.84
-2.03%
USDC(USDC)
€0.86
0.02%
Dogecoin(DOGE)
€0.170707
3.19%
Shiba Inu(SHIB)
€0.000011
-0.74%
Pepe(PEPE)
€0.000010
-1.79%
Peanut das Eichhörnchen(PNUT)
€0.246234
7.19%
Nach oben scrollen