logo

MUSTANG_PANDA__2022__MustangPanda_-_Enemy_at_the_gate_final.pdf

ID: 11fe7a38-b7aa-4025-a9a7-184c4a688952

STIX ID: report--11fe7a38-b7aa-4025-a9a7-184c4a688952

Threat Score

85/100

Uploaded: 2026-08-19

Published Date: 2022-09-20

Last Modified Date: 2022-09-20

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
This report analyzes Mustang Panda (Chinese state-linked APT) campaigns that deployed PlugX/Hodur/THOR variants against Vietnamese and other regional targets. It contains static and dynamic analysis of loader DLLs (log.dll), encrypted payloads (log.dat), shellcode emulation and dumping, PlugX decompression and config decryption, C2s and configuration extraction, delivery via malicious LNKs and decoy documents, and several IOCs and sample hashes.