Mustang Panda, a Chinese cyberespionage group, appears to be using a new malicious custom backdoor called “MQsTTang” in its attacks.

Mustang Panda, also known as TA416 and Bronze President, is an Advanced Persistent Threat (APT) group that carries out theft attacks data around the world using modified variants of the PlugX malware.
Mustang Panda's recently discovered MQsTTang backdoor malware is unlike anything previously observed, suggesting that hackers created it to evade detection and conceal their identity.
See also: Chick-fil-A: Customer accounts hacked
ESET researchers first detected MQsTTang in early January 2023 and it has remained active since then. The new attacks primarily target government and political entities in Europe and Asia, with a primary focus on Taiwan and Ukraine . Mustang Panda has been known to target European government entities since at least 2020 and has further increased its activity in Europe following Russia’s invasion of Ukraine.
Spear-phishing emails are sent to targets to distribute the malware . The malicious payloads come from GitHub repositories created by an individual associated with previous Mustang Panda operations.
The malware has been camouflaged in files RAR, cleverly disguised with names of diplomats and embassies (passport scans, diplomatic notes) to evade detection.
MQsTTang backdoor
ESET characterizes MQsTTang as a “barebones” backdoor that allows attackers to remotely execute commands on the victim ’s machine .
“ This new MQsTTang backdoor provides a kind of remote shell without any of the elements associated with other malware families in this group ,” ESET said in the report
See also: Iron Tiger: They create a Linux version of their custom malware
Upon startup, the malware creates a copy of itself with a command line argument that performs various tasks, such as starting C2 communications, creating persistence, etc.

Persistence is determined by adding a new registry key to “HKCU\Software\Microsoft\Windows\CurrentVersion\Run“, which launches the malware during system startup. After reboot, only the C2 communication task is executed.
An unusual feature of this new backdoor is its use of the MQTT protocol to communicate with the command and control server. MQTT provides the malware resilience to C2 takedowns, hides the attacker's infrastructure, and makes it less likely to be detected by defenders looking for more commonly used C2 protocols.
To remain unnoticed and avoid detection, the MQsTTang backdoor checks for the presence of debugging or monitoring tools on the host computer. If such tools are detected, it changes its behavior.
At this time, we do not know whether the MQsTTang backdoor was developed to carry out a specific malicious campaign or whether it will remain in Mustang Panda's arsenal.
See also: SCARLETEEL Hacker: How do they steal source code and data?
Backdoors pose a serious threat to businesses of all sizes, as they allow cybercriminals to gain unauthorized access to sensitive data and systems without triggering alarms in traditional security measures. The best defense against this type of attack is prevention, which includes keeping systems updated, regularly scanning for potential threats with reliable anti-malware tools, and educating users on good cybersecurity practices. These can go a long way in protecting your business from malicious actors online.
Source: www.bleepingcomputer.com
