Tag: Mustang Panda

Mustang Panda Adds Signed Windows Rootkit to CoolClient Backdoor for Stealth
News

Mustang Panda Adds Signed Windows Rootkit to CoolClient Backdoor for Stealth

An new version of the CoolClient backdoor with a signed Windows kernel-mode rootkit that may conceal and safeguard harmful processes, files, registry objects, and command-and-control (C2) network data has been seen being used by the threat actor HoneyMyte (also known as Mustang Panda). CoolClient was regularly used as a secondary backdoor after a PlugX infection, according to Russian cybersecurity company Kaspersky, which found victims in Myanmar, Mongolia, Pakistan, and Russia, including verified government agencies. When CoolClient has complete access to the Service Control Manager (SCM) and the SeTcbPrivilege privilege, the kernel component is deployed. The malware moves on to the final-stage implant and bypasses driver distribution if those requirements are not satisfied. Add...
Mustang Panda Uses Signed Kernel-Mode Rootkit to Load TONESHELL Backdoor
News

Mustang Panda Uses Signed Kernel-Mode Rootkit to Load TONESHELL Backdoor

In a cyberattack discovered in mid-2025 that targeted an unidentified Asian entity, the Chinese hacker collective Mustang Panda used an undocumented kernel-mode rootkit driver to deliver a new backdoor variant known as TONESHELL. Kaspersky conducted cyber espionage efforts against government agencies in Southeast and East Asia, namely Myanmar and Thailand, and discovered the new backdoor variant. According to the Russian cybersecurity firm, the driver file registers as a minifilter driver on compromised computers and is signed with an outdated, stolen, or compromised digital certificate. Its ultimate objective is to safeguard registry keys, user-mode processes, and harmful files by inserting a backdoor trojan into system processes. TONESHELL, an implant with reverse shell and dow...
Mustang Panda Deploys SnakeDisk USB Worm to Deliver Yokai Backdoor on Thailand IPs
News

Mustang Panda Deploys SnakeDisk USB Worm to Deliver Yokai Backdoor on Thailand IPs

An new version of the backdoor TONESHELL and a hitherto unreported USB worm dubbed SnakeDisk have been seen being used by the China-aligned threat actor Mustang Panda. In an investigation released last week, IBM X-Force experts Golo Mühr and Joshua Chung stated that the worm only runs on machines with IP addresses based in Thailand and opens the Yokai backdoor. Hive0154, also known as BASIN, Bronze President, Camaro Dragon, Earth Preta, HoneyMyte, Polaris, RedDelta, Stately Taurus, and Twill Typhoon, is the cluster being tracked by the tech giant's cybersecurity team. Since at least 2012, the state-sponsored threat actor is thought to have been active. Trend Micro initially made TONESHELL public in November 2022 as a component of cyberattacks that targeted Taiwan, Japan, Australi...
PUBLOAD and Pubshell Malware Used in Mustang Panda’s Tibet-Specific Attack
News

PUBLOAD and Pubshell Malware Used in Mustang Panda’s Tibet-Specific Attack

A new cyber espionage effort targeting the Tibetan community has been traced to Mustang Panda, a threat actor with ties to China. According to IBM X-Force, the spear-phishing attempts took advantage of Tibet-related subjects such the 9th World Parliamentarians' Convention on Tibet (WPCT), China's educational policies in the Tibet Autonomous Region (TAR), and a newly released book by the 14th Dalai Lama. The technology company's cybersecurity branch reported that it had seen the effort earlier this month, which resulted in the deployment of PUBLOAD, a known Mustang Panda virus. The threat actor, Hive0154, is being tracked by it. In addition to articles replicated by Tibetan websites and images from WPCT, the attack chains use Tibet-themed lures to spread a malicious archive read m...
Mustang Panda Deploys Advanced Malware to Spy on Asia-Pacific Governments
News

Mustang Panda Deploys Advanced Malware to Spy on Asia-Pacific Governments

According to new research from Trend Micro, the threat actor known as Mustang Panda has improved the capabilities in its malware toolbox to enable data exfiltration and the delivery of advanced payloads. The cybersecurity company, operating under the moniker Earth Preta, reported that it has detected the spread of PUBLOAD using a worm variant known as HIUPAN. Since early 2022, PUBLOAD has been connected to Mustang Panda as a known downloader malware. It was used to spread the PlugX malware during cyberattacks against government institutions in the Asia-Pacific (APAC) area. According to security researchers Lenart Bermejo, Sunny Lu, and Ted Lee, PUBLOAD was also used to introduce additional tools into the targets' environments read more about Mustang Panda Deploys Advanced Malware...
Mustang Panda Targets Asia with Advanced PlugX Variant DOPLUGS
News

Mustang Panda Targets Asia with Advanced PlugX Variant DOPLUGS

Using a DOPLUGS backdoor, the China-affiliated threat actor Mustang Panda has targeted multiple Asian nations with PlugX (also known as Korplug). In a recent technical write-up, Trend Micro researchers Sunny Lu and Pierre Lee stated that "the piece of customized PlugX malware is dissimilar to the general type of the PlugX malware that contains a completed backdoor command module, and that the former is only used for downloading the latter." Taiwan and Vietnam have been the main targets of DOPLUGS, with smaller percentages being found in Hong Kong, India, Japan, Malaysia, Mongolia, and even China. Mustang Panda, also known as BASIN, Bronze President, Camaro Dragon, Earth Preta, HoneyMyte, RedDelta, Red Lich, Stately Taurus, TA416, and TEMP.Hex, is a tool that is essential to the a...