MUSTANG_PANDA__2023__Eclecticiq_MustangPandaAPT-EUThemed-Lure-PlugX_02-02-2023.pdf
ID: c8ec57a2-fd6b-4ae0-b422-368fae32fdf2
STIX ID: report--c8ec57a2-fd6b-4ae0-b422-368fae32fdf2
Threat Score
85/100
Uploaded: 2026-08-19
Published Date: 2023-03-03
Last Modified Date: 2023-03-03
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
EclecticIQ describes a Mustang Panda espionage campaign using European Commission-themed ISO attachments with malicious LNK files to launch a DLL-hijack-based PlugX loader (LMIGuardianDll.dll) that decrypts and executes an encrypted PlugX payload in-memory, establishes persistence via a HKCU Run key, and communicates with C2 servers (notably 217.12.206.116 and 45.134.83.29); the report includes malware analysis, IOCs (file hashes, filenames, IPs), attack flow, and recommended mitigations.
