Mustang Panda Feeds Worm-Driven USB Attack Strategy
ID: cfe921f0-670a-597d-94d9-5e8bd4569d8d
STIX ID: report--cfe921f0-670a-597d-94d9-5e8bd4569d8d
Feed Name: Dark Reading
Date Published: 2024-09-10
Date Updated: 2026-04-21
Author: Elizabeth Montalbano, Contributing Writer
Trend Micro reports renewed activity from the China-linked APT Mustang Panda (aka Earth Preta) conducting time-sensitive cyber-espionage operations across APAC governments using a self-propagating USB worm (HIUPAN) to distribute a stager (PUBLOAD) and additional tools (FDMTP, PTSOCKET), alongside fast-paced spear‑phishing delivering multistage downloaders that culminate in backdoors (e.g., CBROVER) for persistent access and data exfiltration; researchers provide TTPs and IoCs and warn of ongoing targeted operations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
