logo

Chinese APT Campaign Targets Asia-Pacific with FDMTP Backdoor

ID: ca30e0f7-d0d2-528c-bf46-ba2d026ebfc5

STIX ID: report--ca30e0f7-d0d2-528c-bf46-ba2d026ebfc5

Feed Name: ThreatCluster

Threat Score
75/100

Date Published: 2026-05-14

Date Updated: 2026-05-16

...
...

Chinese APT Mustang Panda is conducting a months‑long espionage campaign against Asia‑Pacific and Japan organizations—notably finance—using an updated FDMTP .NET backdoor (v3.2.5.1). Attackers deliver the payload via DLL sideloading alongside legitimate binaries and use domains impersonating major CDNs; the campaign has been active since September 2025 and remained observed into May 2026, with persistence plugins and extended data retrieval behavior.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.