THREAT OPS › Threat News › Dark Web Profile: Mustang Panda
Dark Web Profile: Mustang Panda
<h1>Dark Web Profile: Mustang Panda</h1> <p><strong>Mustang Panda</strong> is one of the most persistent China-nexus cyber espionage groups operating today. Active since at least <strong>2012</strong>, the group has targeted government agencies, military bodies, diplomatic missions, NGOs, and religious organizations across Southeast Asia, Europe, the Middle East, and the United States, consistentl
Attributed threat actors
- Mustang PandaG0129
MITRE ATT&CK techniques
- Scheduled TaskT1053.005
- Acquire InfrastructureT1583
- Gather Victim Host InformationT1592
- IP AddressesT1590.005
- JavaScriptT1059.007
- Match Legitimate Resource Name or LocationT1036.005
- Boot or Logon Autostart ExecutionT1547
- MalwareT1587.001
- Hide ArtifactsT1564
- Malicious FileT1204.002
- Spearphishing LinkT1566.002
- Spearphishing LinkT1598.003
- Spearphishing AttachmentT1566.001
- System Information DiscoveryT1082
- Application Layer ProtocolT1071
- Scheduled Task/JobT1053
- Native APIT1106
- Replication Through Removable MediaT1091
- Data from Local SystemT1005
- Email AccountsT1586.002
- Exfiltration Over Web ServiceT1567
- DomainsT1583.001
- Social EngineeringT1684
- MasqueradingT1036
- Email AccountsT1585.002
- Command and Scripting InterpreterT1059
- File and Directory DiscoveryT1083
- Web ServiceT1102
- Cloud ServicesT1021.007
- Spearphishing AttachmentT1598.002
- User ExecutionT1204
- Registry Run Keys / Startup FolderT1547.001
- PhishingT1566
- Hijack Execution FlowT1574
- Obfuscated Files or InformationT1027
- Encrypted ChannelT1573
- CredentialsT1589.001
- Bidirectional CommunicationT1102.002
- Exfiltration to Cloud StorageT1567.002
- ImpersonationT1684.001
- Establish AccountsT1585
- Web ProtocolsT1071.001
- Debugger EvasionT1622
- Ingress Tool TransferT1105
- Hidden Files and DirectoriesT1564.001
- Develop CapabilitiesT1587
- Acquire InfrastructureAML.T0008
- Develop CapabilitiesAML.T0017
- Establish AccountsAML.T0021
- Data from Local SystemAML.T0037
- Command and Scripting InterpreterAML.T0050
- ImpersonationAML.T0073
- MasqueradingAML.T0074
Indicators of compromise
- cd9397797216fd4c08df324937509124e57258328c8e4c6d795c6a2cd25b69b0sha256
- fcf4efa82d477c924d42cc6b71aa672ab2381ca256769925ae34dabe2e77e025sha256
- ebd533de7ca16daa70093b0b1084fb6136b6ba091d6ee0e4199762581e1b2e5asha256
- 390148f5157c0f6b337ff19d162c3c2ee3e6d782fdfbe11fb1e411c0684fd33bsha256
- 5f22ec5c14dfd47c92850a5fb3bd8e3754d538b8021b6238238e4020336cfb5csha256
- f53fd0626404a129dcddb8ee7589387dd7bda7999814e0df46c670af6b3da5f5sha256
- a43084f5af861f44c75c5273c779cb26d506cab6b51c33746626da504148a4ecsha256
- f2bed071676feb831ed460489643fd57f6c6c1e0d024a1ea447820276fb13828sha256
- https://www.justice.gov/archives/opa/pr/justice-department-and-fbi-conduct-international-operation-delete-malware-used-china-backedurl
- https://www.acronis.com/en/tru/posts/mustang-panda-targets-indias-government-and-energy-sectors/url
- https://www.cert-in.org.in/url
- 188.208.141.177ipv4
- 188.208.141.196ipv4
- 172.81.60.97ipv4
- accounts.zoho.comdomain
- workdrive.zoho.comdomain
- couldinstallup.comdomain
- editor.gleeze.comdomain
- www.cosmosmusic.comdomain
Original source: https://socradar.io/blog/dark-web-profile-mustang-panda/