Chinese APT Campaign Targets Asia-Pacific with FDMTP Backdoor
ID: ca30e0f7-d0d2-528c-bf46-ba2d026ebfc5
STIX ID: report--ca30e0f7-d0d2-528c-bf46-ba2d026ebfc5
Feed Name: ThreatCluster
Threat Score
Chinese APT Mustang Panda is conducting a months‑long espionage campaign against Asia‑Pacific and Japan organizations—notably finance—using an updated FDMTP .NET backdoor (v3.2.5.1). Attackers deliver the payload via DLL sideloading alongside legitimate binaries and use domains impersonating major CDNs; the campaign has been active since September 2025 and remained observed into May 2026, with persistence plugins and extended data retrieval behavior.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
