logo

Mustang Panda Feeds Worm-Driven USB Attack Strategy

ID: cfe921f0-670a-597d-94d9-5e8bd4569d8d

STIX ID: report--cfe921f0-670a-597d-94d9-5e8bd4569d8d

Feed Name: Dark Reading

Threat Score
85/100

Date Published: 2024-09-10

Date Updated: 2026-04-21

Author: Elizabeth Montalbano, Contributing Writer

...
...

Trend Micro reports renewed activity from the China-linked APT Mustang Panda (aka Earth Preta) conducting time-sensitive cyber-espionage operations across APAC governments using a self-propagating USB worm (HIUPAN) to distribute a stager (PUBLOAD) and additional tools (FDMTP, PTSOCKET), alongside fast-paced spear‑phishing delivering multistage downloaders that culminate in backdoors (e.g., CBROVER) for persistent access and data exfiltration; researchers provide TTPs and IoCs and warn of ongoing targeted operations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.