Chinese Mustang Panda Used Fake Diplomatic Briefings to Spy on Officials
ID: b1b260c8-a200-5268-8c71-1c757bcd303d
STIX ID: report--b1b260c8-a200-5268-8c71-1c757bcd303d
Feed Name: HackRead
Threat Score
In late December 2025–mid January 2026, Dream Research Labs uncovered a Mustang Panda campaign that used spoofed diplomatic briefings (malicious PDFs) to target government officials and international diplomats across Asia and Eastern Europe; the PDFs triggered a PlugX downloader variant (DOPLUGS) which used DLL search-order hijacking and PowerShell to stage additional surveillance tooling, employing custom encryption and loader techniques to remain stealthy.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
