Security News > 2020 > November > Chinese Threat Actor 'Mustang Panda' Updates Tools in Attacks on Vatican

A Chinese threat actor tracked as Mustang Panda was observed using an updated arsenal of tools in recent attacks, Proofpoint's security researchers revealed on Monday.
Also referred to as TA416 and RedDelta, the threat group is known for the targeting of entities connected to the diplomatic relations between the Vatican and the Chinese Communist Party, along with entities in Myanmar, and the new campaign appears to be a continuation of that activity.
Phishing lures used in recent attacks show a focus on the relations between the Vatican and the Chinese Communist Party, as well as spoofed emails imitating journalists from the Union of Catholic Asia News.
The RAR archives used in this campaign include, among others, the encrypted PlugX payload, a legitimate Adobe executable for side loading, and a Golang binary to decrypt and load the payload. According to Proofpoint, this is the first time the adversary has used a Golang binary in their attacks.
The malware variant used in these attacks remains consistent when compared to previously observed versions, as does the command and control communication in these PlugX samples.
News URL
Related news
- Chinese espionage tools deployed in RA World ransomware attack (source)
- ⚡ THN Weekly Recap: Top Cybersecurity Threats, Tools and Tips [13 January] (source)
- ⚡ THN Weekly Recap: Top Cybersecurity Threats, Tools and Tips [20 January] (source)
- ⚡ THN Weekly Recap: Top Cybersecurity Threats, Tools and Tips [27 January] (source)
- ⚡ THN Weekly Recap: Top Cybersecurity Threats, Tools and Tips [3 February] (source)
- ⚡ THN Weekly Recap: Top Cybersecurity Threats, Tools and Tips [10 February] (source)
- Threat Actors Exploit ClickFix to Deploy NetSupport RAT in Latest Cyber Attacks (source)
- RA World Ransomware Attack in South Asia Links to Chinese Espionage Toolset (source)
- Chinese Hackers Exploit MAVInject.exe to Evade Detection in Targeted Cyber Attacks (source)
- FatalRAT Phishing Attacks Target APAC Industries Using Chinese Cloud Services (source)