logo

Weaponizing Conflict: ThreatLabz Exposes Mustang Panda’s Rapid PlugX Campaign in the Middle East

ID: 00203262-63a0-5647-aa92-a663f4512d4d

STIX ID: report--00203262-63a0-5647-aa92-a663f4512d4d

Feed Name: securityonline.info

Threat Score
85/100

Date Published: 2026-03-16

Date Updated: 2026-04-23

Author: Ddos

...
...

**ThreatLabz** reports a China-nexus APT campaign (attributed with medium confidence to Mustang Panda) that began on March 1, 2026 targeting Persian Gulf countries using Arabic-language document lures and LNK/CHM droppers to deliver heavily obfuscated shellcode and a modernized PlugX backdoor which uses HTTPS for C2 and DNS-over-HTTPS for resolution; the campaign employs control flow flattening and mixed Boolean arithmetic to hinder analysis, and defenders are advised to exercise caution, monitor for advanced obfuscation and unusual HTTPS/DoH traffic, and validate document origins.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.