MUSTANG_PANDA__2022__Mustang_Panda_Uses_the_Russian-Ukrainian_War_to_Attack_Europe_and_Asia_Pacific_Targets.pdf
ID: 6b8859f3-be58-4015-a29e-72c1379c9854
STIX ID: report--6b8859f3-be58-4015-a29e-72c1379c9854
Threat Score
88/100
Uploaded: 2026-08-19
Published Date: 2022-12-07
Last Modified Date: 2022-12-07
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
**Executive summary:** BlackBerry Threat Research documents an active Mustang Panda campaign using current-event political lures (RAR containing .LNK shortcuts) and DLL search-order hijacking to load an encrypted payload and execute the PlugX backdoor in memory; the analysis provides loader behavior (EnumSystemCodePagesW usage), file and network IoCs (file hashes, C2 IPs such as 5.34.178.156 and associated SSL certificate pivots), targeted regions (EU and APAC) and a mapped MITRE ATT&CK matrix.
