← Back to all campaigns
ActiveMITRE ATT&CK

RedDelta Modified PlugX Infection Chain Operations

RedDelta Modified PlugX Infection Chain Operations was executed by Mustang Panda from mid-2023 through the end of 2024 against multiple entities in East and Southeast Asia. RedDelta Modified PlugX Infection Chain Operations involved phishing to deliver malicious files or links to users prompting follow-on installer downloads to load PlugX on victim machines in a persistent state.

First observedJul 1, 2023
Last observedDec 1, 2024
Attributed actors1
Source-backed events3
Attribution

Who has been linked to this activity

Each relationship retains its own confidence and source.

Source ReportedActive actor

Mustang Panda

Mustang Panda is a China-based cyber espionage threat actor that has been conducting operations since at least 2012. Mustang Panda has been known to use tailored phishing lures and decoy documents to deliver malicious...

mitre-attckReview source
Activity

Campaign timeline

Every date says what it measures so catalog dates are not confused with publication dates.

Cataloged
Attribution

Mustang Panda attributed to this campaign

Attribution confidence: Source Reported.

Last observed
Campaign

RedDelta Modified PlugX Infection Chain Operations last observed

The campaign source marks this as the latest known activity date.

MITRE ATT&CKSource
First observed
Campaign

RedDelta Modified PlugX Infection Chain Operations first observed

The campaign source marks this as the beginning of the known activity window.

MITRE ATT&CKSource
About the context below

CVEs, techniques, malware, and indicators in the sections below are associated with an attributed actor. They are useful investigative context, but the campaign source does not necessarily link every item directly to this campaign.

Investigation context

What the attributed actors are known to use

Use this material to guide hunting and prioritization, then confirm each relationship against its cited source.

ATT&CK techniques 85

Malware and tools 23

  • BOOKWORMMalware | Mustang Panda
  • CANONSTAGERMalware | Mustang Panda
  • CLAIMLOADERMalware | Mustang Panda
  • China ChopperMalware | Mustang Panda
  • Cobalt StrikeMalware | Mustang Panda
  • CorKLOGMalware | Mustang Panda
  • HIUPANMalware | Mustang Panda
  • PAKLOGMalware | Mustang Panda
  • PUBLOADMalware | Mustang Panda
  • PlugXMalware | Mustang Panda
  • PoisonIvyMalware | Mustang Panda
  • RCSessionMalware | Mustang Panda

Indicators 11

  • 2d7c8780e97409770a9d4f31c66c9d63MD5 | Mustang Panda
  • 9460e150e1981d5c165043520c5c12feMD5 | Mustang Panda
  • 9717f005c5fb98e08d2ad983d88f94eeMD5 | Mustang Panda
  • CoolClientTOOL | Mustang Panda
  • PlugXTOOL | Mustang Panda
  • ToneShellTOOL | Mustang Panda
  • cert.iniTOOL | Mustang Panda
  • f518d8e5fe70d9090f6280c68a95998fMD5 | Mustang Panda
  • libngs.dllTOOL | Mustang Panda
  • loadcert.iniTOOL | Mustang Panda
  • msagent.sysTOOL | Mustang Panda
Sources

Evidence behind this page

Open the original material before making an attribution or response decision.