T1027 Obfuscated Files or Information |
GroupMustang Panda |
Mustang Panda has delivered initial payloads hidden using archives and encoding measures. Mustang Panda has also utilized opaque predicates in payloads to hinder analysis. |
T1036.007 Double File Extension |
GroupMustang Panda |
Mustang Panda has used an additional filename extension to hide the true file type. |
T1047 Windows Management Instrumentation |
GroupMustang Panda |
Mustang Panda has executed PowerShell scripts via WMI. |
T1053.005 Scheduled Task |
GroupMustang Panda |
Mustang Panda has created a scheduled task to execute additional malicious software, as well as maintain persistence. Mustang Panda has also created a scheduled task that creates a reverse shell. |
T1059.001 PowerShell |
GroupMustang Panda |
Mustang Panda has used malicious PowerShell scripts to enable execution. |
T1059.003 Windows Command Shell |
GroupMustang Panda |
Mustang Panda has executed HTA files via cmd.exe, and used batch scripts for collection. Mustang Panda has also utilized cmd.exe to execute commands on an infected host such as `cmd.exe /c ping.exe 8.8.8.8 -n 70&&"%temp%\FontEDL.exe"`. |
T1059.005 Visual Basic |
GroupMustang Panda |
Mustang Panda has embedded VBScript components in LNK files to download additional files and automate collection. Mustang Panda has also used VBA macros in maldocs to execute malicious DLLs. Mustang Panda also utilized a VBS Script “autorun.vbs” that created persistence through saving the VBS Script in the startup directory which would cause it to run each time the machine was turned on. |
T1071.001 Web Protocols |
GroupMustang Panda |
Mustang Panda has communicated with its C2 via HTTP POST requests. |
T1204.002 Malicious File |
GroupMustang Panda |
Mustang Panda has sent malicious files requiring direct victim interaction to execute. Mustang Panda has also leveraged executable files that display decoy documents to the victim to provide a resemblance of legitimacy with customized themes related to the victim. |
T1218.004 InstallUtil |
GroupMustang Panda |
Mustang Panda has used InstallUtil.exe to execute a malicious Beacon stager. |
T1518 Software Discovery |
GroupMustang Panda |
Mustang Panda has searched the victim system for the InstallUtil.exe program and its version. |
T1574.001 DLL |
GroupMustang Panda |
Mustang Panda has used a legitimately signed executable to execute a malicious payload within a DLL file. Mustang Panda has abused legitimate executables to side-load malicious DLLs. |