#MustangPandaMAVInject
China's Mustang Panda used MAVInject.exe to inject TONESHELL malware (via IRSetup.exe & decoy PDF) into waitfor.exe, bypassing ESET. The Thailand-targeting attack communicated with militarytc[.]com:443.#MustangPandaMAVInject
February 18, 2025 at 4:06 PM