The China-linked Mustang Panda actor has been linked to a cyber assault concentrating on a Philippines authorities entity amid rising tensions between the 2 international locations over the disputed South China Sea.
Palo Alto Networks Unit 42 attributed the adversarial collective to 3 campaigns in August 2023, primarily singling out organizations within the South Pacific.
“The campaigns leveraged reputable software program together with Strong PDF Creator and SmadavProtect (an Indonesian-based antivirus resolution) to sideload malicious information,” the corporate mentioned.
“Menace authors additionally creatively configured the malware to impersonate reputable Microsoft visitors for command and management (C2) connections.”
Mustang Panda, additionally tracked underneath the names Bronze President, Camaro Dragon, Earth Preta, RedDelta, and Stately Taurus, is assessed to be a Chinese language superior persistent menace (APT) energetic since no less than 2012, orchestrating cyber espionage campaigns concentrating on non-governmental organizations (NGOs) and authorities our bodies throughout North America, Europe, and Asia.
In late September 2023, Unit 42 additionally implicated the menace actor to assaults geared toward an unnamed Southeast Asian authorities to distribute a variant of a backdoor referred to as TONESHELL.
The most recent campaigns leverage spear-phishing emails to ship a malicious ZIP archive file that incorporates a rogue dynamic-link library (DLL) that is launched utilizing a method referred to as DLL side-loading. The DLL subsequently establishes contact with a distant server.
It is assessed that the Philippines authorities entity was doubtless compromised over a five-day interval between August 10 and 15, 2023.
Using SmadavProtect is a identified tactic adopted by Mustang Panda in current months, having deployed malware expressly designed to bypass the security resolution.
“Stately Taurus continues to show its capacity to conduct persistent cyberespionage operations as some of the energetic Chinese language APTs,” the researchers mentioned.
“These operations goal a wide range of entities globally that align with geopolitical subjects of curiosity to the Chinese language authorities.”
The disclosure comes as a South Korean APT actor named Higaisa has been uncovered concentrating on Chinese language customers by means of phishing web sites mimicking well-known software program functions resembling OpenVPN.
“As soon as executed, the installer drops and runs Rust-based malware on the system, subsequently triggering a shellcode,” Cyble mentioned late final month. “The shellcode performs anti-debugging and decryption operations. Afterward, it establishes encrypted command-and-control (C&C) communication with a distant Menace Actor (TA).”