logo

MUSTANG_PANDA__2022__Cisco_Talos_Intelligence_Group_-_Comprehensive_Threat_Intelligence_Mustang_Panda_deploys_a_new_wave_of_malware_targeting_Europe.pdf

ID: 02b1c914-ace6-46fb-804a-e31fbdee54f2

STIX ID: report--02b1c914-ace6-46fb-804a-e31fbdee54f2

Threat Score

88/100

Uploaded: 2026-08-19

Published Date: 2022-05-13

Last Modified Date: 2022-05-13

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Mustang Panda (China-linked APT) ran 2022 phishing campaigns targeting European, Asian and U.S. organizations using topical lures (EU/Ukraine, summits, government reports) to deliver PlugX RAT, custom DLL loaders, bespoke stagers, Meterpreter payloads and TCP reverse shells. The Talos report documents infection chains (downloaders, archive sideloading, LNK/maldoc vectors), technical analysis of loaders/stagers and shellcode, and provides extensive IOCs (file hashes, IPs, URLs) and mitigation recommendations for detection and prevention.