Weaponizing Conflict: ThreatLabz Exposes Mustang Panda’s Rapid PlugX Campaign in the Middle East
ID: 00203262-63a0-5647-aa92-a663f4512d4d
STIX ID: report--00203262-63a0-5647-aa92-a663f4512d4d
Feed Name: securityonline.info
**ThreatLabz** reports a China-nexus APT campaign (attributed with medium confidence to Mustang Panda) that began on March 1, 2026 targeting Persian Gulf countries using Arabic-language document lures and LNK/CHM droppers to deliver heavily obfuscated shellcode and a modernized PlugX backdoor which uses HTTPS for C2 and DNS-over-HTTPS for resolution; the campaign employs control flow flattening and mixed Boolean arithmetic to hinder analysis, and defenders are advised to exercise caution, monitor for advanced obfuscation and unusual HTTPS/DoH traffic, and validate document origins.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
