ATT&CKReferencesAvira Mustang Panda January 2020

Avira Mustang Panda January 2020

Hamzeloofard, S. (2020, January 31). New wave of PlugX targets Hong Kong | Avira Blog. Retrieved April 13, 2021.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples14

TechniqueUsed byProcedure example
T1016
System Network Configuration Discovery
GroupMustang Panda

Mustang Panda has used ipconfig and arp to determine network configuration information. Mustang Panda has also utilized SharpNBTScan to scan the victim environment.

T1027.016
Junk Code Insertion
GroupMustang Panda

Mustang Panda has used junk code within their DLL files to hinder analysis.

T1049
System Network Connections Discovery
GroupMustang Panda

Mustang Panda has used netstat -ano to determine network connection information.

T1052.001
Exfiltration over USB
GroupMustang Panda

Mustang Panda has used a customized PlugX variant which could exfiltrate documents from air-gapped networks.

T1057
Process Discovery
GroupMustang Panda

Mustang Panda has used tasklist /v to determine active process information. Mustang Panda has also used TONESHELL malware to check the process name and process path to ensure it matches the expected one prior to triggering a custom exception handler.

T1059.003
Windows Command Shell
GroupMustang Panda

Mustang Panda has executed HTA files via cmd.exe, and used batch scripts for collection. Mustang Panda has also utilized cmd.exe to execute commands on an infected host such as `cmd.exe /c ping.exe 8.8.8.8 -n 70&&"%temp%\FontEDL.exe"`.

T1074.001
Local Data Staging
GroupMustang Panda

Mustang Panda has stored collected credential files in c:\windows\temp prior to exfiltration. Mustang Panda has also stored documents for exfiltration in a hidden folder on USB drives.

T1082
System Information Discovery
GroupMustang Panda

Mustang Panda has gathered system information using systeminfo.

T1083
File and Directory Discovery
GroupMustang Panda

Mustang Panda has searched the entire target system for DOC, DOCX, PPT, PPTX, XLS, XLSX, and PDF files.

T1091
Replication Through Removable Media
GroupMustang Panda

Mustang Panda has used a customized PlugX variant which could spread through USB connections.

T1204.002
Malicious File
GroupMustang Panda

Mustang Panda has sent malicious files requiring direct victim interaction to execute. Mustang Panda has also leveraged executable files that display decoy documents to the victim to provide a resemblance of legitimacy with customized themes related to the victim.

T1560.001
Archive via Utility
GroupMustang Panda

Mustang Panda has used RAR to create password-protected archives of collected documents prior to exfiltration. Mustang Panda has used WinRAR “Rar.exe” to archive stolen files before exfiltration. Mustang Panda has also used TONESHELL and post-exploitation tools such as RemCom and Impacket to execute WinRAR `rar.exe` to archive files for exfiltration.

T1560.003
Archive via Custom Method
GroupMustang Panda

Mustang Panda has encrypted documents with RC4 prior to exfiltration.

T1564.001
Hidden Files and Directories
GroupMustang Panda

Mustang Panda's PlugX variant has created a hidden folder on USB drives named RECYCLE.BIN to store malicious executables and collected data. Mustang Panda has also modified file attributes to `hidden` and `system`.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.