Mustang Panda Abuses Legitimate Apps to Target Myanmar Based Victims

[correlate]

Level 18
Thread author
Top Poster
Well-known
May 4, 2019
801
The BlackBerry Research & Intelligence Team recently uncovered a campaign by an advanced persistent threat (APT) group called Mustang Panda that is leveraging the PlugX malware family to target the Southeast Asian state of Myanmar.

Our team analyzed the samples in question and found their embedded configurations revealed a set of command-and-control (C2) domains that masquerade as Myanmar news outlets. This is not the first time a campaign targeting this state has impersonated Myanmar news outlets or used PlugX malware.

These tactics, techniques, and procedures (TTPs), along with other corroborating evidence – such as a previous indication that the group was active in this reasonable location – lead us to assert with confidence that the China-based threat group known as Mustang Panda is responsible for this campaign
 

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top