logo

Chinese hackers use new data theft malware in govt attacks

ID: 5c4bb05e-4478-5f83-aba9-c844ee64ec7e

STIX ID: report--5c4bb05e-4478-5f83-aba9-c844ee64ec7e

Feed Name: Bleeping Computer

Threat Score
85/100

Date Published: 2024-09-09

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

Trend Micro observed Mustang Panda (aka Earth Preta) evolving its operations with new malware and tactics: a HIUPAN worm variant spreads PUBLOAD via removable drives, FDMTP is deployed via DLL side‑loading, and PTSOCKET or cURL is used for exfiltration; separate spear‑phishing campaigns deliver DOWNBAIT/PULLBAIT and a signed backdoor (CBROVER). The actor targets government and related organizations (primarily APAC), focuses on harvesting office documents and other sensitive files, and has published a comprehensive IoC list.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.