China-Linked Hackers Target Myanmar's Top Ministries with Backdoor Blitz
ID: 2e5a33b8-6cb5-5ff9-8013-41d07f061a9c
STIX ID: report--2e5a33b8-6cb5-5ff9-8013-41d07f061a9c
Feed Name: The Hacker News
CSIRT-CTI attributes twin November 2023 and January 2024 campaigns targeting Myanmar's Ministry of Defence and Foreign Affairs to Mustang Panda (aka Stately Taurus). The adversary used legitimate signed software (B&R binary) susceptible to DLL search-order hijacking, ISO/LNK lure files, and bespoke loaders (PUBLOAD, TONESHELL) to deploy PlugX and other backdoors, with C2 traffic disguised as Windows Update headers; the activity aligns with prior Mustang Panda operations and geopolitical motives.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
