Feb. 2, 2023, 10 a.m. | EclecticIQ Threat Research Team

Security Boulevard securityboulevard.com


EXECUTIVE SUMMARY



  • Since at least 2019, the Mustang Panda threat actor group has targeted government and public sector organizations across Asia and Europe [3] with long-term cyberespionage campaigns in line with strategic interests of the Chinese government.

  • In November 2022, Mustang Panda shifted from using archive files to using malicious optical disc image (ISO) files containing a shortcut (LNK) file to deliver the modified version of PlugX malware. This switch increases the evasion against anti-malware solutions [2].

  • The Mustang …

actor apt archive asia campaigns chinese chinese government cyberespionage disc europe european commission executive files government intelligence research iso lnk malicious malware mustang panda november organizations panda plugx plugx malware public public sector sector strategic threat threat actor threats and vulnerabilities threats & breaches trojan version vulnerabilities

SOC 2 Manager, Audit and Certification

@ Deloitte | US and CA Multiple Locations

Information Security Engineers

@ D. E. Shaw Research | New York City

Security Officer Level 1 (L1)

@ NTT DATA | Virginia, United States of America

Alternance - Analyste VOC - Cybersécurité - Île-De-France

@ Sopra Steria | Courbevoie, France

Senior Security Researcher, SIEM

@ Huntress | Remote US or Remote CAN

Cyber Security Engineer Lead

@ ASSYSTEM | Bridgwater, United Kingdom