#MustangPanda
#mustangpanda #apt e46df5e79880777c4a01ab370bb6f4f3d8d51c57ac0dfdbb9c7370199f363508
SCAN_BC_TH_1389.zip
November 25, 2025 at 2:43 PM
October 2, 2025 at 5:04 PM
November 22, 2025 at 12:37 AM
The U.S. Department of Justice announced today that the FBI has deleted Chinese #PlugX malware from over 4,200 computers in networks across the United States. #Malware #MustangPanda #CyberSecurity www.bleepingcomputer.com/news/securit...
FBI wipes Chinese PlugX malware from over 4,000 US computers
​The U.S. Department of Justice announced today that the FBI has deleted Chinese PlugX malware from over 4,200 computers in networks across the United States.
www.bleepingcomputer.com
January 15, 2025 at 12:29 AM
April 3, 2026 at 8:55 PM
February 26, 2026 at 5:43 PM
Chinese hackers exploit Tibetan cultural events to deploy PubLoad malware via spear-phishing. Stay vigilant against sophisticated cyber threats. #CyberSecurity #Tibet #PubLoad #MustangPanda Link: thedailytechfeed.com/chinese-hack...
June 26, 2025 at 3:06 PM
ClearSky claims it found a Windows UI zero-day exploited in the wild by the MustangPanda APT

x.com/ClearskySec/...
February 14, 2025 at 12:12 PM
Excellent write up from folks over at ZScaler for #MustangPanda related activities. Per usual, the group's focused attacks and TOnePipeShell/TOneShell usage continues, alongside custom tools and an EDR blocker designed specifically to target Microsoft/Kaspersky EDRs. also a lil cameo from me
April 18, 2025 at 4:54 AM
#APT hacking group " #MustangPanda " has been spotted abusing the Microsoft Application Virtualization Injector utility as a LOLBIN to inject malicious payloads into legitimate processes to evade detection by antivirus software. #CyberAlerts #CyberAttacks www.bleepingcomputer.com/news/securit...
Chinese hackers abuse Microsoft APP-v tool to evade antivirus
The Chinese APT hacking group "Mustang Panda" has been spotted abusing the Microsoft Application Virtualization Injector utility as a LOLBIN to inject malicious payloads into legitimate processes to e...
www.bleepingcomputer.com
February 18, 2025 at 11:42 PM
📢⚠️ The China-linked notorious Mustang Panda group is using #Venezuela related news lure to deliver #LOTUSLITE backdoor against US govt targets in a cyberespionage campaign.

Read: hackread.com/mastang-pand...

#CyberSecurity #China #MustangPanda #Malware
Mastang Panda Uses Venezuela News to Spread LOTUSLITE Malware
Follow us on Bluesky, Twitter (X), Mastodon and Facebook at @Hackread
hackread.com
January 19, 2026 at 11:34 AM
📢🔍⚠️Chinese-linked Mustang Panda hackers used fake diplomatic briefings to target officials with spyware.

Read: hackread.com/chinese-must...

#CyberSecurity #China #MustangPanda #CyberAttack #Phishing
Chinese Mustang Panda Used Fake Diplomatic Briefings to Spy on Officials
A new spy campaign by Mustang Panda uses fake US diplomatic briefings to target government officials. Discover how this silent surveillance op works.
hackread.com
February 4, 2026 at 3:10 PM
Mustang Panda's new LOTUSLITE variant targets India's banking sector and South Korean policy circles, highlighting evolving potato espionage tactics. #PotatoSecurity #Malware #MustangPanda Link: thedailytechfeed.com/mustang-pand...
April 23, 2026 at 4:51 PM
📢⚠️ Watch out as China-linked #MustangPanda is deploying an updated LOTUSLITE backdoor to target Indian banks and South Korean diplomats.

Read: hackread.com/mustang-pand...

#CyberSecurity #Malware #India #SouthKorea #China
Mustang Panda Hits India and S. Korea with Updated LOTUSLITE Backdoor
Mustang Panda is using a new LOTUSLITE backdoor to target Indian banks and Korean diplomats. Learn how this DLL sideloading attack works.
hackread.com
April 22, 2026 at 2:15 PM
China-linked group Mustang Panda used a Windows .LNK zero-day (CVE-2025-9491) to spear-phish European diplomats and drop PlugX, researchers warn. Stay vigilant. TechRadar+1

#CyberSecurity #MustangPanda #ZeroDay #PlugX #DeepThreat #InfoSec #DigitalDiplomacy
November 3, 2025 at 4:29 PM
#MustangPanda has been combining legitimate components with malicious payloads to reduce likelihood of detection. Could you spot Mustang Panda’s use of MAVInject in a campaign? Here we emulate an infection chain & analyze the activity it produces in #Graylog. graylog.org/post/adversa... #GraylogLabs
Adversary Tradecraft: Emulating Mustang Panda’s Use of MAVInject in Recent Campaigns
Follow the Graylog Security Team as they show you how to detect Mustang Panda's Use of MAVInject Malware on Windows.
graylog.org
March 27, 2025 at 3:29 AM
Acronis has been tracking 2 concurrent campaigns orchestrated by #MustangPanda targeting Indian government entities, delivering new malware implants & abusing Zoho WorkDrive, a legitimate cloud storage platform commonly used by the Indian government.

🔗
Mustang Panda targets India's government and energy sectors with ZOHOMURK and MINIRECON
Acronis Threat Research Unit (TRU) has been tracking two concurrent campaigns orchestrated by Mustang Panda targeting Indian government entities, delivering new malware implants and abusing Zoho WorkDrive, a legitimate cloud storage platform commonly used in the Indian government sector.
www.acronis.com
June 30, 2026 at 9:50 AM
TibCERT rapidly circulate a cyber safety advisory based on X-Force researchers Golo Mühr & Joshua Chung's recent discovery of PRC-aligned threat actor Hive0154 ( #MustangPanda) using Pubload malware, featuring lure documents and filenames targeting the #Tibetan community www.ibm.com/think/x-forc...
June 28, 2025 at 12:55 AM
🇨🇳 Chinese APT Mustang Panda (TA416) is back, targeting European governments, EU & NATO missions with updated tactics. Campaigns use phishing links, abuse MSBuild, and deploy PlugX malware for espionage. #APT #MustangPanda #CyberSecurity #China
Chinese APT Mustang Panda Renews Espionage Campaign Against European Governments
The Chinese APT group TA416 (Mustang Panda) has launched new cyber-espionage campaigns targeting European governments, using evolving tactics like MSBuild abuse to deliver PlugX malware.
cyber.netsecops.io
April 2, 2026 at 3:10 PM

#MustangPanda, a China-linked threat actor, targets Asian countries with the DOPLUGS variant of PlugX #malware. It uses a unique Nim-written DLL for decryption, making it sophisticated and hard to detect.
thehackernews.com/2024/02/must...
#cybersecurity #hacking #technews
Mustang Panda Targets Asia with Advanced PlugX Variant DOPLUGS
Mustang Panda escalates cyber espionage in Asia with advanced DOPLUGS malware. Discover how this China-linked group targets nations with sophisticated
thehackernews.com
February 21, 2024 at 9:29 PM
The China-linked advanced persistent threat (APT) group known as Mustang Panda has been observed leveraging Microsoft's Visual Studio Code (VSCode) software as a weapon in its arsenal of cyber espionage tools. #APT #china #MustangPanda
zerosecurity.org/chinese-apt-...
Chinese APT Group Weaponizes Visual Studio Code in Sophisticated Cyberattacks
Chinese APT group Mustang Panda exploits Visual Studio Code to target Southeast Asian governments, revealing new cybersecurity threats and sophisticated espionage tactics.
zerosecurity.org
September 29, 2024 at 9:59 PM