logo

Chinese APT Mustang Panda Debuts 4 New Attack Tools

ID: 14bdc016-c358-535e-92ee-961944247116

STIX ID: report--14bdc016-c358-535e-92ee-961944247116

Feed Name: Dark Reading

Threat Score
85/100

Date Published: 2025-04-18

Date Updated: 2026-04-21

Author: Nate Nelson, Contributing Writer

...
...

Mustang Panda (TA416), a Chinese state‑linked APT, has refreshed its toolkit as observed in a recent attack on a Myanmar organization: researchers uncovered two new keyloggers (PAKLOG, CorKLOG), an upgraded ToneShell backdoor (v3), a lateral-movement proxy (StarProxy) using FakeTLS, and a kernel driver (SplatCloak) deployed via SplatDropper that disables AV callbacks — indicating continued targeted espionage with improved evasion and persistence capabilities.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.