Sudeep Singh. (2025, April 16). Latest Mustang Panda Arsenal: ToneShell and StarProxy | P1. Retrieved July 21, 2025.
Not cited by any technique.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1001.003 Protocol or Service Impersonation |
GroupMustang Panda | Mustang Panda has utilized TLS record headers in network packets to impersonate various versions of TLS protocols to blend in with legitimate network traffic. Mustang Panda has used FakeTLS to communicate with its C2 servers. |
| T1001.003 Protocol or Service Impersonation |
MalwareTONESHELL | TONESHELL used FakeTLS headers in network packets to impersonate various versions of TLS protocols to blend in with legitimate network traffic. TONESHELL variants have utilized FakeTLS headers with the bytes `0x17 0x03 0x03` to represent TLSv1.2 and `0x17 0x03 0x04` for TLSv1.3. |
| T1001.003 Protocol or Service Impersonation |
MalwareStarProxy | StarProxy has utilized TLS record headers in network packets to impersonate various versions of TLS protocols to blend in with legitimate network traffic. StarProxy used FakeTLS to communicate with its C2 server. |
| T1027 Obfuscated Files or Information |
GroupMustang Panda | Mustang Panda has delivered initial payloads hidden using archives and encoding measures. Mustang Panda has also utilized opaque predicates in payloads to hinder analysis. 2022 November_TrendMicro_Earth Preta_Toneshell_PubloadAnomali MUSTANG PANDA October 2019Cisco Talos MUSTANG PANDA PLUGX PUBLOAD MAY 2022Crowdstrike MUSTANG PANDA June 2018Eset PlugX Korplug Mustang Panda March 2022Proofpoint TA416 Europe March 2022Proofpoint TA416 November 2020Recorded Future REDDELTA July 2020Secureworks BRONZE PRESIDENT December 2019Sophos PlugX September 2022Unit42 Bookworm Nov2015ZscalerZscaler PAKLOG CorkLog SplatCloak Splatdropper April 2025 |
| T1027.001 Binary Padding |
MalwareTONESHELL | TONESHELL has used randomized padding to obfuscate payloads. |
| T1027.007 Dynamic API Resolution |
MalwareTONESHELL | TONESHELL has utilized a modified DJB2 algorithm to resolve APIs. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareTONESHELL | TONESHELL has renamed malicious files to mimic legitimate file names and file extensions. TONESHELL has also masqueraded as legitimate file names to include LogMeIn.dll. |
| T1055.001 Dynamic-link Library Injection |
MalwareTONESHELL | TONESHELL has used DLL injection to execute payloads received from the C2 server. |
| T1059 Command and Scripting Interpreter |
MalwareStarProxy | StarProxy has used the command line for execution of commands. |
| T1059.003 Windows Command Shell |
MalwareTONESHELL | TONESHELL has created a reverse shell using `cmd.exe`. |
| T1070.004 File Deletion |
MalwareTONESHELL | TONESHELL has deleted payload files received from the C2 server. |
| T1082 System Information Discovery |
MalwareTONESHELL | TONESHELL has the ability to retrieve the name of the infected machine. |
| T1087 Account Discovery |
MalwareTONESHELL | TONESHELL included functionality to retrieve a list of user accounts. |
| T1090.001 Internal Proxy |
MalwareStarProxy | StarProxy has proxied traffic between infected devices and their C2 servers. |
| T1095 Non-Application Layer Protocol |
MalwareStarProxy | StarProxy has used TCP for C2 communications to target IPs or domains. StarProxy contained code to support both UDP and TCP connections. |
| T1106 Native API |
MalwareStarProxy | StarProxy has used native windows API calls such as `GetLocalTime()` to retrieve system data. |
| T1106 Native API |
MalwareTONESHELL | TONESHELL has utilized Native Windows API functions such as `WriteProcessMemory` and `CreateRemoteThreadEx`. TONESHELL has also utilized Windows API functions for creating seed values including `CoCreateGuid` and `GetTickCount`. TONESHELL has leveraged the legitimate API function `EnumSystemLocalesA` to run its shellcode through the callback function. |
| T1106 Native API |
GroupMustang Panda | Mustang Panda has used various Windows API calls during execution and defense evasion. 2022 November_TrendMicro_Earth Preta_Toneshell_Pubload2025_IBM_PUBLOAD_TONESHELL_HIUPAN_CLAIMLOADER_MUSTANG PANDABroadcomEset PlugX Korplug Mustang Panda March 2022Google Threat Intelligence Group MUSTANG PANDA PLUGX August 2025IBM MUSTANG PANDA PUBLOAD CLAIMLOADER JUNE 2025Lab52 MUSTANG PANDA PUBLOAD MAY 2023Palo Alto Networks, Unit 42Sophos Mustang Panda PLUGXTrend Micro Mustang Panda Earth Preta Toneshell February 2025ZscalerZscaler PAKLOG CorkLog SplatCloak Splatdropper April 2025 |
| T1124 System Time Discovery |
MalwareStarProxy | StarProxy has utilized the windows API call `GetLocalTime()` to retrieve a SystemTime structure to generate a seed value. |
| T1134.002 Create Process with Token |
MalwareTONESHELL | TONESHELL included functionality to create sub-processes with a specific user’s token. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareTONESHELL | TONESHELL has decoded its payload prior to execution. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareStarProxy | StarProxy has decrypted network packets using a custom algorithm. |
| T1480.001 Environmental Keying |
MalwareTONESHELL | TONESHELL has generated unique GUIDs to identify victim devices. TONESHELL has leveraged environmental keying in payload delivery using the victim computer name and other configuration values. TONESHELL has also tracked IDs associated with reverse shell subprocesses to manage interactions and terminations from C2. |
| T1553.002 Code Signing |
GroupMustang Panda | Mustang Panda has used valid legitimate digital signatures and certificates to evade detection. |
| T1573.001 Symmetric Cryptography |
MalwareStarProxy | StarProxy has leveraged two 256-byte XOR keys to encrypt and decrypt network packets using a custom algorithm. |
| T1573.001 Symmetric Cryptography |
MalwareTONESHELL | TONESHELL has used RC4 encryption in C2 communications. TONESHELL variants used a randomly generated variable length (0x20 - 0x200 bytes) rolling XOR key to encrypt and decrypt network packets. |
| T1574.001 DLL |
MalwareStarProxy | StarProxy has been side-loaded by the legitimate, signed executable, IsoBurner.exe. |
| T1574.001 DLL |
GroupMustang Panda | Mustang Panda has used a legitimately signed executable to execute a malicious payload within a DLL file. Mustang Panda has abused legitimate executables to side-load malicious DLLs. 2022 November_TrendMicro_Earth Preta_Toneshell_Pubload2025_IBM_PUBLOAD_TONESHELL_HIUPAN_CLAIMLOADER_MUSTANG PANDAAnomali MUSTANG PANDA October 2019BroadcomCSIRT CTI MUSTANG PANDA PUBLOAD TONESHELL JAN 2024Cisco Talos MUSTANG PANDA PLUGX PUBLOAD MAY 2022EclecticIQ Mustang Panda PlugXEset PlugX Korplug Mustang Panda March 2022Google Threat Intelligence Group MUSTANG PANDA PLUGX August 2025IBM MUSTANG PANDA PUBLOAD CLAIMLOADER JUNE 2025Lab52 MUSTANG PANDA PUBLOAD MAY 2023Palo Alto Unit42 STATELY TAURUS TONESHELL September 2023Proofpoint TA416 November 2020Recorded Future REDDELTA July 2020Sophos PlugX September 2022Trend Micro Mustang Panda Earth Preta Toneshell February 2025Unit42 Bookworm Nov2015ZscalerZscaler PAKLOG CorkLog SplatCloak Splatdropper April 2025 |
| T1574.001 DLL |
MalwareTONESHELL | TONESHELL has abused legitimate executables to side-load malicious DLLs. TONESHELL has also been loaded via DLL side-loading, using legitimate, signed executables to include: FastVD.exe, Bandizip.exe and gpgconf.exe. 2022 November_TrendMicro_Earth Preta_Toneshell_PubloadATTACKIQ MUSTANG PANDA TONESHELL March 2023CSIRT CTI MUSTANG PANDA PUBLOAD TONESHELL JAN 2024Palo Alto Unit42 STATELY TAURUS TONESHELL September 2023Trend Micro Mustang Panda Earth Preta TONESHELL June 2023Trend Micro Mustang Panda Earth Preta Toneshell February 2025Zscaler |
| T1678 Delay Execution |
MalwareTONESHELL | TONESHELL has the ability to pause operations for a specified duration prior to follow-on execution of activities. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.