Earth Preta’s Campaign Abusing MAVInject to Bypass Detection (Campaign)
ID: 2ba87fe1-b332-587e-a9ab-dedafc8f327e
STIX ID: report--2ba87fe1-b332-587e-a9ab-dedafc8f327e
Feed Name: Wiz Cloud Threat Landscape
Date Published: 2025-02-18
Date Updated: 2026-05-01
Author: [email protected] (Wiz Threat Research)
Earth Preta (Mustang Panda) is observed conducting a targeted campaign against Asia-Pacific government entities using spear-phishing with decoy PDFs and DLL side-loading to deploy a TONESHELL backdoor. The group abuses a legitimate EA executable (OriginLegacyCLI.exe) for sideloading and leverages Microsoft Application Virtualization Injector (MAVInject.exe) to inject malicious code into waitfor.exe when ESET antivirus processes are detected, otherwise using WriteProcessMemory and CreateRemoteThreadEx. The malware decrypts shellcode from its .data section, establishes C2 to www.militarytc.com:443, and exfiltrates system information while supporting remote commands for shells and file manipulation, demonstrating refined persistence and detection-evasion TTPs.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
