Chinese APT Mustang Panda Debuts 4 New Attack Tools
ID: 14bdc016-c358-535e-92ee-961944247116
STIX ID: report--14bdc016-c358-535e-92ee-961944247116
Feed Name: Dark Reading
Threat Score
Mustang Panda (TA416), a Chinese state‑linked APT, has refreshed its toolkit as observed in a recent attack on a Myanmar organization: researchers uncovered two new keyloggers (PAKLOG, CorKLOG), an upgraded ToneShell backdoor (v3), a lateral-movement proxy (StarProxy) using FakeTLS, and a kernel driver (SplatCloak) deployed via SplatDropper that disables AV callbacks — indicating continued targeted espionage with improved evasion and persistence capabilities.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
