Mustang Panda's Latest Cyberespionage Campaign: New Tools and Tactics
N2K NetworksMay 24, 202517 min185 views
35 connectionsΒ·40 entities in this videoβDeep Dive into Mustang Panda's New Campaign
- π― Mustang Panda, a Chinese-origin threat group, has been observed targeting government, military, and minority groups, primarily in East Asia, with recent campaigns also showing activity in Europe.
- π‘ Zscaler ThreatLabz research uncovered new tools and updated tactics used by the group, including backdoors, proxy tools, keyloggers, and EDR evasion techniques.
New Backdoors and Proxy Tools
- π¦ Tone Shell is an updated backdoor with enhanced stealth capabilities, featuring modified fake TLS command and control communication protocols and new methods for storing infected machine identifiers.
- π Star Proxy is a newly discovered lateral movement tool designed to proxy traffic and facilitate attacker communication, enabling propagation to adjacent devices within a compromised environment.
Evasion and Persistence Techniques
- π Fake TLS traffic imitation and custom encryption methods are employed to disguise command and control communications and evade pattern-based detection engines.
- π DLL code injection allows malicious code to run as part of legitimate processes, though this is often detectable by EDRs.
- π PAKLOG and CorKLOG are custom keyloggers used by Mustang Panda to maintain persistence and gather user input.
- π‘οΈ SplatCloak is an evasion tool specifically designed to disable or circumvent EDR functionalities, further enhancing the group's stealth.
Attack Stages and Defense Strategies
- π Threat actors typically follow four stages: attack surface discovery, initial compromise, lateral movement, and data exfiltration.
- π‘οΈ A defense-in-depth strategy is crucial, combining network-layer inspection with full TLS inspection, proper network segmentation to minimize lateral propagation, and inline DLP solutions for data exfiltration monitoring.
- π‘ While AI wasn't directly observed in this campaign, its increasing use by threat actors necessitates defenders leveraging AI to fight AI for efficiency and efficacy.
Measuring Success and Sophistication
- π Zscaler's visibility into Mustang Panda's activities comes from their Zero Trust Exchange, utilizing advanced controls like sandboxing for payload detonation and deception technology (honeypots) to detect hands-on keyboard activity.
- π Mustang Panda is considered well-resourced and is continuously improving its tooling and stealth capabilities, indicating a growing level of sophistication.
Knowledge graph40 entities Β· 35 connections
How they connect
An interactive map of every person, idea, and reference from this conversation. Hover to trace connections, click to explore.
Hover Β· drag to explore
40 entities
Chapters7 moments
Key Moments
Transcript63 segments
Full Transcript
Topics15 themes
Whatβs Discussed
Mustang PandaCyberespionageThreat IntelligenceZscaler ThreatLabzTone ShellStar ProxyPAKLOGCorKLOGSplatCloakPhishingBackdoorLateral MovementEDR EvasionTLS InspectionZero Trust
Smart Objects40 Β· 35 links
CompaniesΒ· 3
ProductsΒ· 8
PeopleΒ· 2
ConceptsΒ· 23
LocationsΒ· 4