MUSTANG_PANDA__2022__Cisco_Talos_Intelligence_Group_-_Comprehensive_Threat_Intelligence_Mustang_Panda_deploys_a_new_wave_of_malware_targeting_Europe.pdf
ID: 02b1c914-ace6-46fb-804a-e31fbdee54f2
STIX ID: report--02b1c914-ace6-46fb-804a-e31fbdee54f2
Threat Score
88/100
Uploaded: 2026-08-19
Published Date: 2022-05-13
Last Modified Date: 2022-05-13
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Mustang Panda (China-linked APT) ran 2022 phishing campaigns targeting European, Asian and U.S. organizations using topical lures (EU/Ukraine, summits, government reports) to deliver PlugX RAT, custom DLL loaders, bespoke stagers, Meterpreter payloads and TCP reverse shells. The Talos report documents infection chains (downloaders, archive sideloading, LNK/maldoc vectors), technical analysis of loaders/stagers and shellcode, and provides extensive IOCs (file hashes, IPs, URLs) and mitigation recommendations for detection and prevention.
