ATT&CKReferencesAnomali MUSTANG PANDA October 2019

Anomali MUSTANG PANDA October 2019

Anomali Threat Research. (2019, October 7). China-Based APT Mustang Panda Targets Minority Groups, Public and Private Sector Organizations. Retrieved April 12, 2021.

Open the source

Techniques0

Not cited by any technique.

Groups1

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples12

TechniqueUsed byProcedure example
T1027
Obfuscated Files or Information
GroupMustang Panda

Mustang Panda has delivered initial payloads hidden using archives and encoding measures. Mustang Panda has also utilized opaque predicates in payloads to hinder analysis.

T1036.007
Double File Extension
GroupMustang Panda

Mustang Panda has used an additional filename extension to hide the true file type.

T1047
Windows Management Instrumentation
GroupMustang Panda

Mustang Panda has executed PowerShell scripts via WMI.

T1053.005
Scheduled Task
GroupMustang Panda

Mustang Panda has created a scheduled task to execute additional malicious software, as well as maintain persistence. Mustang Panda has also created a scheduled task that creates a reverse shell.

T1059.001
PowerShell
GroupMustang Panda

Mustang Panda has used malicious PowerShell scripts to enable execution.

T1059.003
Windows Command Shell
GroupMustang Panda

Mustang Panda has executed HTA files via cmd.exe, and used batch scripts for collection. Mustang Panda has also utilized cmd.exe to execute commands on an infected host such as `cmd.exe /c ping.exe 8.8.8.8 -n 70&&"%temp%\FontEDL.exe"`.

T1059.005
Visual Basic
GroupMustang Panda

Mustang Panda has embedded VBScript components in LNK files to download additional files and automate collection. Mustang Panda has also used VBA macros in maldocs to execute malicious DLLs. Mustang Panda also utilized a VBS Script “autorun.vbs” that created persistence through saving the VBS Script in the startup directory which would cause it to run each time the machine was turned on.

T1071.001
Web Protocols
GroupMustang Panda

Mustang Panda has communicated with its C2 via HTTP POST requests.

T1204.002
Malicious File
GroupMustang Panda

Mustang Panda has sent malicious files requiring direct victim interaction to execute. Mustang Panda has also leveraged executable files that display decoy documents to the victim to provide a resemblance of legitimacy with customized themes related to the victim.

T1218.004
InstallUtil
GroupMustang Panda

Mustang Panda has used InstallUtil.exe to execute a malicious Beacon stager.

T1518
Software Discovery
GroupMustang Panda

Mustang Panda has searched the victim system for the InstallUtil.exe program and its version.

T1574.001
DLL
GroupMustang Panda

Mustang Panda has used a legitimately signed executable to execute a malicious payload within a DLL file. Mustang Panda has abused legitimate executables to side-load malicious DLLs.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.