logo

Mustang Panda Linked to Updated FDMTP Backdoor in Asia-Pacific Espionage Campaign

ID: 9da491a9-467d-5991-bf15-295af752c4a7

STIX ID: report--9da491a9-467d-5991-bf15-295af752c4a7

Feed Name: Infosecurity Magazine (News)

Threat Score
85/100

Date Published: 2026-05-14

Date Updated: 2026-05-14

...
...

Darktrace observed a months-long espionage campaign (Sep 2025–Apr 2026) attributed with moderate confidence to Mustang Panda targeting Asia-Pacific and Japan. Attackers impersonated CDN infrastructure to deliver legitimate binaries alongside malicious DLLs (DLL sideloading), then loaded a heavily obfuscated .NET backdoor (FDMTP v3.2.5.1) in-memory; the backdoor uses a custom TCP Duplex Message Transport Protocol (DMTP), supports modular plugins (task scheduling, registry persistence, loader, remote file/process manipulation), and maintains persistence via scheduled tasks, HKCU\Software\Microsoft\IME registry entries and polling icloud-cdn.net for updates. Defenders are advised to prioritize detection of the behavioral execution sequence over static indicators.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.