logo

Mustang Panda Launches PlugX RAT Campaign via Fake Browser Update

ID: 3c082aac-c264-5e34-a866-7620c2e4a302

STIX ID: report--3c082aac-c264-5e34-a866-7620c2e4a302

Feed Name: ThreatCluster

Threat Score
75/100

Date Published: 2026-06-02

Date Updated: 2026-06-05

...
...

Mustang Panda has launched a high-severity campaign deploying the PlugX RAT via a fake browser updater; the attack uses a multi-stage LNK + PowerShell loader to sideload PlugX through a G DATA antivirus binary and beacons to a hard-coded HTTPS C2 with layered encryption, prompting monitoring of LNK/PowerShell activity and unusual HTTPS connections.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.