A sophisticated Chinese state-sponsored threat actor, Mustang Panda, has implemented a new attack strategy utilizing legitimate Windows tools to bypass security measures. The group’s latest technique involves Microsoft Application Virtualization Injector (MAVInject.exe) to inject malicious payloads into the waitfor.exe process.
Key Attack Components:
– Initial dropper: IRSetup.exe
– Legitimate Electronic Arts application (OriginLegacyCLI.exe)
– Modified TONESHELL backdoor (EACore.dll)
– Target focus: Thailand-based users
Attack Methodology:
1. Deployment of multiple files including decoy PDF documents
2. Utilization of Setup Factory for payload execution
3. Sideloading of malicious DLL through legitimate EA application
4. Process injection using MAVInject.exe
5. Command and control communication through militarytc[.]com:443
Southeast Asian Connection:
Recent investigations revealed infrastructure overlaps with Bookworm malware targeting ASEAN organizations. The attacks utilize:
– PUBLOAD downloader malware
– DLL side-loading techniques
– Shared code similarities between Bookworm and TONESHELL backdoor
ESET Response:
ESET has contested claims about their antivirus being bypassed, stating:
– The technique is not novel
– Existing protection against the reported method
– Prior detection capabilities implemented since January
– Attribution to China-aligned CeranaKeeper APT Group
The malware’s versatility and continuous evolution suggest potential future appearances in targeted attacks across Southeast Asia.
