New attacks attributed to the China -based Mustang Panda cyberespionage group show that the threat actor turned to two new tools, called FDMTP and PTSOCKET, to download the PUBLOAD and HIUPAN malware, and steal information from compromised networks.
See also: North Korean hackers distribute COVERTCATCH malware

Researchers discovered that hackers are using a variant of the HIUPAN to deliver the PUBLOAD malware stager via removable drives on the network.
Mustang Panda, (also known as HoneyMyte/Broze President/Earth Preta/Polaris/Stately Taurus) is a Chinese state-run hacking that focuses on cyberespionage operations against government and non-government entities primarily in the Asia-Pacific region, but also in other regions.
Mustang Panda typically uses spear-phishing for initial access, but in a recently published report, researchers at cybersecurity firm Trend Micro say that new attacks from the threat actor spread PUBLOAD across the network via removable drives infected with a variant of the HIUPAN malware.
HIUPAN hides its presence by moving all of its files to a hidden directory and leaving only a seemingly legitimate file (“USBConfig.exe”) visible on the drive to trick the user into executing it.
See also: SpyAgent: New Android malware steals crypto wallet recovery phrases
PUBLOAD is the main control tool in the attacks. It executes on the system via DLL sideloading, establishes persistence by modifying the Windows , and then executes special reconnaissance commands to map the network.

In addition to PUBLOAD, Mustang Panda used a new malware called FDMTP, which acts as a secondary control tool. Researchers say that FDMTP is embedded in the data section of a DLL and can also be deployed via DLL sideloading.
According to researchers, data collection in more recent Mustang Panda attacks is done in RAR files and targets .DOC, .DOCX, .XLS, .XLSX, .PDF, .PPT, and .PPTX.
The malicious actor infiltrates information via PUBLOAD using the cURL. However, there is also an alternative to the custom tool PTSOCKET, an application based on TouchSocket.
See also: New Emansrepo malware targets Windows users
Malware, such as PUBLOAD used by Mustang Panda, refers to any program or code that is intentionally designed to disrupt, damage, or gain unauthorized access to computer systems or networks. This type of software includes a variety of forms, including viruses, worms, trojans, ransomware , and spyware. Each type works differently and has different goals, from stealing sensitive information to locking users out of their systems until a ransom is paid. Protection against malware requires a combination of strong cybersecurity measures, up-to-date software , and user education to recognize potential threats and suspicious activity.
Source: bleepingcomputer
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
