ATT&CKReferencesPalo Alto Networks, Unit 42

Palo Alto Networks, Unit 42

Robert Falcone. (2025, February 20). Stately Taurus Activity in Southeast Asia Links to Bookworm Malware. Retrieved July 21, 2025.

Open the source

Techniques0

Not cited by any technique.

Groups1

Software1

Campaigns0

None recorded.

Procedure examples21

TechniqueUsed byProcedure example
T1001.003
Protocol or Service Impersonation
MalwarePUBLOAD

PUBLOAD has modified HTTP POST requests to resemble legitimate communications. PUBLOAD used FakeTLS headers in network packets to impersonate various versions of TLS protocols to blend in with legitimate network traffic. PUBLOAD has utilized FakeTLS headers with the bytes 17 03 03.

T1001.003
Protocol or Service Impersonation
MalwareBOOKWORM

BOOKWORM has modified HTTP POST requests to resemble legitimate communications.

T1027.013
Encrypted/Encoded File
MalwareBOOKWORM

BOOKWORM has utilized Base64 encoding to obfuscate its payload.

T1027.015
Compression
MalwarePUBLOAD

PUBLOAD has been delivered as compressed files within ZIP files to victims.

T1070.006
Timestomp
GroupMustang Panda

Mustang Panda has modified file timestamps from the export address table (EAT) in malware to make it difficult to identify creation times.

T1070.006
Timestomp
MalwareBOOKWORM

BOOKWORM has modified file timestamps from the export address table (EAT) to make it difficult to discern when the module was created.

T1071.001
Web Protocols
MalwarePUBLOAD

PUBLOAD has communicated via `curl` over HTTP to identify device IP data. PUBLOAD has also utilized HTTP for a command-and-control protocol through HTTP POST. PUBLOAD has also leveraged HTTPS for C2.

T1071.001
Web Protocols
MalwareBOOKWORM

BOOKWORM has communicated with its C2 via HTTP POST requests.

T1105
Ingress Tool Transfer
MalwarePUBLOAD

PUBLOAD has acted as a stager that can download the next-stage payload from its C2 server. PUBLOAD has also delivered FDMTP as a secondary control tool and PTSOCKET for exfiltration to some infected systems.

T1106
Native API
MalwarePUBLOAD

PUBLOAD has used various Windows API calls during execution, when establishing persistence and defense evasion. PUBLOAD stager leveraged Windows API functions with callback including `GrayStringW`, `EnumDateFormatsA`, and `LineDDA` to bypass anti-virus monitoring. PUBLOAD has also utilized other native windows API functions with callback functions such as `EnumChildWindows` and `EnumSystemLanguageGroupsA`.

T1106
Native API
MalwareBOOKWORM

BOOKWORM has used various Windows API calls during execution and defense evasion. BOOKWORM has created a buffer on the heap using `HeapCreate` and `HeapAlloc` which allows for copying of shell code and then execution on the heap is initiated through callback function of legitimate API functions such as `EnumChildWindows` or `EnumSystemLanguageGroupsA`.

T1106
Native API
MalwareTONESHELL

TONESHELL has utilized Native Windows API functions such as `WriteProcessMemory` and `CreateRemoteThreadEx`. TONESHELL has also utilized Windows API functions for creating seed values including `CoCreateGuid` and `GetTickCount`. TONESHELL has leveraged the legitimate API function `EnumSystemLocalesA` to run its shellcode through the callback function.

T1106
Native API
GroupMustang Panda

Mustang Panda has used various Windows API calls during execution and defense evasion.

T1140
Deobfuscate/Decode Files or Information
MalwarePUBLOAD

PUBLOAD has decoded its payload prior to execution.

T1140
Deobfuscate/Decode Files or Information
GroupMustang Panda

Mustang Panda has the ability to decrypt its payload prior to execution. Mustang Panda has also utilized RC4 encryption for malicious payloads.

T1140
Deobfuscate/Decode Files or Information
MalwareBOOKWORM

BOOKWORM has decoded its Base64 encoded payload prior to execution. BOOKWORM has also encrypted files with RC4 and has decrypted its payload prior to execution.

T1204.002
Malicious File
GroupMustang Panda

Mustang Panda has sent malicious files requiring direct victim interaction to execute. Mustang Panda has also leveraged executable files that display decoy documents to the victim to provide a resemblance of legitimacy with customized themes related to the victim.

T1553.002
Code Signing
GroupMustang Panda

Mustang Panda has used valid legitimate digital signatures and certificates to evade detection.

T1574.001
DLL
MalwarePUBLOAD

PUBLOAD has abused legitimate executables to side-load malicious DLLs.

T1574.001
DLL
MalwareBOOKWORM

BOOKWORM has used DLL side-loading to execute the malicious payload. BOOKWORM has also side-loaded DLL components into a legitimate process, including Microsoft Malware Protection `MsMpEng.exe` and Kaspersky Anti-Virus `ushata.exe`.

T1583.001
Domains
GroupMustang Panda

Mustang Panda has acquired C2 domains prior to operations.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.