ATT&CKReferencesPalo Alto Unit42 STATELY TAURUS TONESHELL September 2023

Palo Alto Unit42 STATELY TAURUS TONESHELL September 2023

Lior Rochberger, Tom Fakterman, Robert Falcone. (2023, September 22). Cyberespionage Attacks Against Southeast Asian Government Linked to Stately Taurus, Aka Mustang Panda. Retrieved September 9, 2025.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples28

TechniqueUsed byProcedure example
T1003
OS Credential Dumping
GroupMustang Panda

Mustang Panda utilized “Hdump” to dump credentials from memory.

T1003.001
LSASS Memory
GroupMustang Panda

Mustang Panda has harvested credentials from memory of lssas.exe with Mimikatz.

T1003.003
NTDS
GroupMustang Panda

Mustang Panda has used vssadmin to create a volume shadow copy and retrieve the NTDS.dit file. Mustang Panda has also used reg save on the SYSTEM file Registry location to help extract the NTDS.dit file.

T1003.006
DCSync
GroupMustang Panda

Mustang Panda has leveraged Mimikatz DCSync feature to obtain user credentials.

T1018
Remote System Discovery
GroupMustang Panda

Mustang Panda has queried Active Directory for computers using AdFind. Mustang Panda has also utilized SharpNBTScan to scan the victim environment.

T1036.004
Masquerade Task or Service
MalwareTONESHELL

TONESHELL has masqueraded as the legitimate Windows utility service DISMsrv (Dism Images Servicing Utility Service).

T1046
Network Service Discovery
GroupMustang Panda

Mustang Panda has leveraged NBTscan to scan IP networks.

T1048.003
Exfiltration Over Unencrypted Non-C2 Protocol
GroupMustang Panda

Mustang Panda has used FTP to exfiltrate archive files.

T1053.005
Scheduled Task
MalwareTONESHELL

TONESHELL has created scheduled tasks to maintain persistence.

T1056.001
Keylogging
MalwareTONESHELL

TONESHELL has capabilities to conduct keylogging.

T1059.005
Visual Basic
GroupMustang Panda

Mustang Panda has embedded VBScript components in LNK files to download additional files and automate collection. Mustang Panda has also used VBA macros in maldocs to execute malicious DLLs. Mustang Panda also utilized a VBS Script “autorun.vbs” that created persistence through saving the VBS Script in the startup directory which would cause it to run each time the machine was turned on.

T1069.002
Domain Groups
GroupMustang Panda

Mustang Panda has leveraged AdFind to enumerate domain groups.

T1072
Software Deployment Tools
GroupMustang Panda

Mustang Panda has leveraged legitimate software tools such as AntiVirus Agents, Security Services, and App Development tools to execute scripts and to side-load dlls.

T1083
File and Directory Discovery
GroupMustang Panda

Mustang Panda has searched the entire target system for DOC, DOCX, PPT, PPTX, XLS, XLSX, and PDF files.

T1087.002
Domain Account
GroupMustang Panda

Mustang Panda has utilized AdFind to identify domain users.

T1105
Ingress Tool Transfer
MalwareTONESHELL

TONESHELL has the ability to download additional files to the victim device.

T1113
Screen Capture
MalwareTONESHELL

TONESHELL has conducted screen capturing.

T1505.003
Web Shell
GroupMustang Panda

Mustang Panda has used China Chopper web shells to maintain access to victims’ environments.

T1543.003
Windows Service
MalwareTONESHELL

TONESHELL has created a malicious service DISMsrv to maintain persistence.

T1547.001
Registry Run Keys / Startup Folder
MalwareTONESHELL

TONESHELL has added Registry Run keys to achieve persistence.

T1559
Inter-Process Communication
MalwareTONESHELL

TONESHELL has facilitated inter-process communication between DLL components via the use of pipes. TONESHELL has also created a reverse shell using two anonymous pipes to write data to stdin and read data from stdout and stderr.

T1560.001
Archive via Utility
MalwareTONESHELL

TONESHELL used WinRAR rar.exe to archive files for exfiltration. TONESHELL has also utilized a unique 13-character password consisting of upper lower case and digits to protect RAR archives.

T1560.001
Archive via Utility
GroupMustang Panda

Mustang Panda has used RAR to create password-protected archives of collected documents prior to exfiltration. Mustang Panda has used WinRAR “Rar.exe” to archive stolen files before exfiltration. Mustang Panda has also used TONESHELL and post-exploitation tools such as RemCom and Impacket to execute WinRAR `rar.exe` to archive files for exfiltration.

T1567.002
Exfiltration to Cloud Storage
GroupMustang Panda

Mustang Panda has also exfiltrated archived files to cloud services such as Dropbox using `curl`.

T1574.001
DLL
MalwareTONESHELL

TONESHELL has abused legitimate executables to side-load malicious DLLs. TONESHELL has also been loaded via DLL side-loading, using legitimate, signed executables to include: FastVD.exe, Bandizip.exe and gpgconf.exe.

T1574.001
DLL
GroupMustang Panda

Mustang Panda has used a legitimately signed executable to execute a malicious payload within a DLL file. Mustang Panda has abused legitimate executables to side-load malicious DLLs.

T1588.002
Tool
GroupMustang Panda

Mustang Panda has obtained and leveraged publicly-available tools for intrusion activities.

T1654
Log Enumeration
GroupMustang Panda

Mustang Panda has used Wevtutil to gather Windows Security Event Logs.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.