logo

Chinese hackers abuse Microsoft APP-v tool to evade antivirus

ID: b491ee58-bf28-51c4-831e-13baaa7ac546

STIX ID: report--b491ee58-bf28-51c4-831e-13baaa7ac546

Feed Name: Bleeping Computer

Threat Score
78/100

Date Published: 2025-02-18

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

The report describes Mustang Panda (Earth Preta) using Microsoft Application Virtualization Injector (MAVInject.exe) as a LOLBIN to inject a modified TONESHELL backdoor (EACore.dll) into the legitimate waitfor.exe process, deployed via a Setup Factory dropper (IRSetup.exe) sent in spear-phishing targeting Asia-Pacific government entities; Trend Micro observed 200+ victims since 2022 and ESET disputes the claim that the technique effectively bypasses its AV products.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.