HomeSecurityMustang Panda: Uses Google Drive to drop malware on...

Mustang Panda: Uses Google Drive to drop malware on govt networks

The Chinese group Mustang Panda launched a spearphishing campaign that delivered customized malware stored on Google Drive to government, research, and academic organizations around the world.

Mustang Panda google drive

The attacks, which took place between March and October of the following year, are linked to the cyber espionage group Mustang Panda.

See also: Windows zero day exploit to drop Qbot software

Based on Trend Micro's research, it appears that the main targets of this group are organizations located in Australia, Japan, Taiwan, Myanmar, and the Philippines.

Mustang Panda: Uses Google Drive to drop malware on govt networks

Chinese hackers sent their targets emails from Google accounts, with subject lines containing false information that would trick the reader into downloading malware from a Google Drive link.

Information about infection

According to Trend Micro researchers in their report today, hackers mainly used messages with geopolitical themes and mainly targeted government/legal organizations (84% of cases).

See also: AXLoker ransomware: Hacks Discord accounts

The cybercriminal uses an embedded link that points to a Google Drive or Dropboxin order to bypass security mechanisms, as these platforms usually have a good reputation and are less suspicious.

These links lead to the download of compressed files containing malware strains such as ToneShell, ToneIns, and PubLoad.

Mustang Panda google drive

“According to the report, the subject of the email may be blank or have the same malicious name as the file.”

Although hackers used various malware loading routines, the process typically involved DLL sideloading after the victim launched an executable in the files. A decoy document is displayed in the foreground to minimize suspicion.

Mustang Panda: Uses Google Drive to drop malware on govt networks

The evolution of malware

The three malware strains used in this campaign are PubLoad, ToneIns, and ToneShell.

Of the three types of custom malware used in this campaign, only PubLoad has been previously analyzed. This was in a Cisco Talos report from May 2022, which described campaigns against European targets.

PubLoad is a malware that is responsible for creating persistence by adding registry keys and creating scheduled tasks. It also decrypts shellcode and handles command and control (C2) communications.

Trend Micro later discovered that PubLoad had more sophisticated anti-analysis mechanisms, suggesting that the Mustang Panda team was still actively working on the tool.

See also: SEO poisoning attack via Google Data Studio

ToneIns is an installer used to install ToneShell, which is the main backdoor used in recent cyberattacks. By using obfuscation, it is able to evade detection while allowing attackers to maintain persistence on an infected system.

ToneShell is a backdoor that loads directly into memory and features code flow obfuscation through the implementation of custom exception handlers.

This also acts as an anti-sandbox, as the backdoor is not executed in a debug environment.

Mustang Panda google drive

After connecting to the C2, ToneShell sends a packet with the victim's ID data and then waits patiently for new instructions.

These commands allow you to upload and download files, create shells for intranet data exchange , change the sleep configuration, and much more

Mustang Panda team activity

Trend Micro discovered that the recent campaign uses the same Mustang Panda techniques, tactics, and procedures (TTPs) as those reported by Secureworks in September last year.

The hackers' recent campaign shows better tools and the ability to reach more targets, allowing them to collect information and break into systems.

Proofpoint reported earlier this year that the Mustang Panda group was focusing its activities in Europe, specifically targeting high-ranking diplomats.

Although they have short-term bursts of focused activity, the Chinese espionage gang Mustang Panda is a global threat, as ESET's March 2022 research shows us. Their activities have explored Southeast Asia, Southern Europe , and Africa.

What is Spearphishing?

Spearphishing is a type of email scam that targets specific individuals or organizations. Unlike phishing scams, which send out mass emails in the hopes of “snapping” a few victims, spearphishers go to great lengths to craft carefully tailored emails that are designed to trick the recipient into thinking they are coming from a trusted source.

Information source: bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Teo Ehc
Teo Ehchttps://www.secnews.gr
Be the limited edition.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS