MUSTANG_PANDA__2022__Mustang_Panda_Abuses_Legitimate_Apps_to_Target_Myanmar_Based_Victims.pdf
ID: 27d60005-7235-4600-b273-551960ec66bd
STIX ID: report--27d60005-7235-4600-b273-551960ec66bd
Threat Score
85/100
Uploaded: 2026-08-19
Published Date: 2022-12-07
Last Modified Date: 2022-12-07
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
BlackBerry Research & Intelligence describes a Mustang Panda APT campaign targeting Myanmar and other countries using PlugX RAT delivered in RAR archives that bundle legitimate signed applications, malicious DLL loaders, and encrypted DAT payloads; the actors use DLL search-order hijacking to side-load and execute PlugX, with C2 infrastructure masquerading as Myanmar news domains, and the report includes IoCs (hashes, domains, IPs), a YARA rule, MITRE mappings, and mitigation guidance.
