StarProxy

S1227

Malware.View on attack.mitre.org

About this malware

StarProxy is custom malware used by Mustang Panda as a post-compromise tool, to enable proxying of traffic between the infected machine and other machines on the same network.

Techniques used9

Procedure examples9

TechniqueProcedure example
T1001.003
Protocol or Service Impersonation

StarProxy has utilized TLS record headers in network packets to impersonate various versions of TLS protocols to blend in with legitimate network traffic. StarProxy used FakeTLS to communicate with its C2 server.

T1059
Command and Scripting Interpreter

StarProxy has used the command line for execution of commands.

T1090.001
Internal Proxy

StarProxy has proxied traffic between infected devices and their C2 servers.

T1095
Non-Application Layer Protocol

StarProxy has used TCP for C2 communications to target IPs or domains. StarProxy contained code to support both UDP and TCP connections.

T1106
Native API

StarProxy has used native windows API calls such as `GetLocalTime()` to retrieve system data.

T1124
System Time Discovery

StarProxy has utilized the windows API call `GetLocalTime()` to retrieve a SystemTime structure to generate a seed value.

T1140
Deobfuscate/Decode Files or Information

StarProxy has decrypted network packets using a custom algorithm.

T1573.001
Symmetric Cryptography

StarProxy has leveraged two 256-byte XOR keys to encrypt and decrypt network packets using a custom algorithm.

T1574.001
DLL

StarProxy has been side-loaded by the legitimate, signed executable, IsoBurner.exe.

Groups that use it1

Campaigns0

None recorded.

References1

  1. Zscaler Open source
    Sudeep Singh. (2025, April 16). Latest Mustang Panda Arsenal: ToneShell and StarProxy | P1. Retrieved July 21, 2025.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.