logo

Chinese Mustang Panda Used Fake Diplomatic Briefings to Spy on Officials

ID: b1b260c8-a200-5268-8c71-1c757bcd303d

STIX ID: report--b1b260c8-a200-5268-8c71-1c757bcd303d

Feed Name: HackRead

Threat Score
88/100

Date Published: 2026-02-04

Date Updated: 2026-04-22

Author: Deeba Ahmed

...
...

In late December 2025–mid January 2026, Dream Research Labs uncovered a Mustang Panda campaign that used spoofed diplomatic briefings (malicious PDFs) to target government officials and international diplomats across Asia and Eastern Europe; the PDFs triggered a PlugX downloader variant (DOPLUGS) which used DLL search-order hijacking and PowerShell to stage additional surveillance tooling, employing custom encryption and loader techniques to remain stealthy.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.