Mustang Panda Launches PlugX RAT Campaign via Fake Browser Update
ID: 533ea52b-26ff-5ff7-b326-f6634ddbd04d
STIX ID: report--533ea52b-26ff-5ff7-b326-f6634ddbd04d
Feed Name: ThreatCluster
Threat Score
Mustang Panda is conducting an active campaign deploying the PlugX RAT using a fake browser updater and a multi-stage LNK/PowerShell loader that sideloads the malware through a legitimate G DATA antivirus binary; the malware beacons to a hard-coded C2 over HTTPS with layered encryption, and defenders are advised to monitor LNK/PowerShell activity, suspicious HTTPS connections, and implement application whitelisting and user education.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
