Zscaler

Sudeep Singh. (2025, April 16). Latest Mustang Panda Arsenal: ToneShell and StarProxy | P1. Retrieved July 21, 2025.

Open the source

Techniques0

Not cited by any technique.

Groups1

Software2

Campaigns0

None recorded.

Procedure examples30

TechniqueUsed byProcedure example
T1001.003
Protocol or Service Impersonation
GroupMustang Panda

Mustang Panda has utilized TLS record headers in network packets to impersonate various versions of TLS protocols to blend in with legitimate network traffic. Mustang Panda has used FakeTLS to communicate with its C2 servers.

T1001.003
Protocol or Service Impersonation
MalwareTONESHELL

TONESHELL used FakeTLS headers in network packets to impersonate various versions of TLS protocols to blend in with legitimate network traffic. TONESHELL variants have utilized FakeTLS headers with the bytes `0x17 0x03 0x03` to represent TLSv1.2 and `0x17 0x03 0x04` for TLSv1.3.

T1001.003
Protocol or Service Impersonation
MalwareStarProxy

StarProxy has utilized TLS record headers in network packets to impersonate various versions of TLS protocols to blend in with legitimate network traffic. StarProxy used FakeTLS to communicate with its C2 server.

T1027
Obfuscated Files or Information
GroupMustang Panda

Mustang Panda has delivered initial payloads hidden using archives and encoding measures. Mustang Panda has also utilized opaque predicates in payloads to hinder analysis.

T1027.001
Binary Padding
MalwareTONESHELL

TONESHELL has used randomized padding to obfuscate payloads.

T1027.007
Dynamic API Resolution
MalwareTONESHELL

TONESHELL has utilized a modified DJB2 algorithm to resolve APIs.

T1036.005
Match Legitimate Resource Name or Location
MalwareTONESHELL

TONESHELL has renamed malicious files to mimic legitimate file names and file extensions. TONESHELL has also masqueraded as legitimate file names to include LogMeIn.dll.

T1055.001
Dynamic-link Library Injection
MalwareTONESHELL

TONESHELL has used DLL injection to execute payloads received from the C2 server.

T1059
Command and Scripting Interpreter
MalwareStarProxy

StarProxy has used the command line for execution of commands.

T1059.003
Windows Command Shell
MalwareTONESHELL

TONESHELL has created a reverse shell using `cmd.exe`.

T1070.004
File Deletion
MalwareTONESHELL

TONESHELL has deleted payload files received from the C2 server.

T1082
System Information Discovery
MalwareTONESHELL

TONESHELL has the ability to retrieve the name of the infected machine.

T1087
Account Discovery
MalwareTONESHELL

TONESHELL included functionality to retrieve a list of user accounts.

T1090.001
Internal Proxy
MalwareStarProxy

StarProxy has proxied traffic between infected devices and their C2 servers.

T1095
Non-Application Layer Protocol
MalwareStarProxy

StarProxy has used TCP for C2 communications to target IPs or domains. StarProxy contained code to support both UDP and TCP connections.

T1106
Native API
MalwareStarProxy

StarProxy has used native windows API calls such as `GetLocalTime()` to retrieve system data.

T1106
Native API
MalwareTONESHELL

TONESHELL has utilized Native Windows API functions such as `WriteProcessMemory` and `CreateRemoteThreadEx`. TONESHELL has also utilized Windows API functions for creating seed values including `CoCreateGuid` and `GetTickCount`. TONESHELL has leveraged the legitimate API function `EnumSystemLocalesA` to run its shellcode through the callback function.

T1106
Native API
GroupMustang Panda

Mustang Panda has used various Windows API calls during execution and defense evasion.

T1124
System Time Discovery
MalwareStarProxy

StarProxy has utilized the windows API call `GetLocalTime()` to retrieve a SystemTime structure to generate a seed value.

T1134.002
Create Process with Token
MalwareTONESHELL

TONESHELL included functionality to create sub-processes with a specific user’s token.

T1140
Deobfuscate/Decode Files or Information
MalwareTONESHELL

TONESHELL has decoded its payload prior to execution.

T1140
Deobfuscate/Decode Files or Information
MalwareStarProxy

StarProxy has decrypted network packets using a custom algorithm.

T1480.001
Environmental Keying
MalwareTONESHELL

TONESHELL has generated unique GUIDs to identify victim devices. TONESHELL has leveraged environmental keying in payload delivery using the victim computer name and other configuration values. TONESHELL has also tracked IDs associated with reverse shell subprocesses to manage interactions and terminations from C2.

T1553.002
Code Signing
GroupMustang Panda

Mustang Panda has used valid legitimate digital signatures and certificates to evade detection.

T1573.001
Symmetric Cryptography
MalwareStarProxy

StarProxy has leveraged two 256-byte XOR keys to encrypt and decrypt network packets using a custom algorithm.

T1573.001
Symmetric Cryptography
MalwareTONESHELL

TONESHELL has used RC4 encryption in C2 communications. TONESHELL variants used a randomly generated variable length (0x20 - 0x200 bytes) rolling XOR key to encrypt and decrypt network packets.

T1574.001
DLL
MalwareStarProxy

StarProxy has been side-loaded by the legitimate, signed executable, IsoBurner.exe.

T1574.001
DLL
GroupMustang Panda

Mustang Panda has used a legitimately signed executable to execute a malicious payload within a DLL file. Mustang Panda has abused legitimate executables to side-load malicious DLLs.

T1574.001
DLL
MalwareTONESHELL

TONESHELL has abused legitimate executables to side-load malicious DLLs. TONESHELL has also been loaded via DLL side-loading, using legitimate, signed executables to include: FastVD.exe, Bandizip.exe and gpgconf.exe.

T1678
Delay Execution
MalwareTONESHELL

TONESHELL has the ability to pause operations for a specified duration prior to follow-on execution of activities.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.