Chinese Hackers Weaponize Windows Tool to Bypass ESET Antivirus in Stealthy Attacks


Chinese APT Group Mustang Panda Employs New Evasion Techniques

A sophisticated Chinese state-sponsored threat actor, Mustang Panda, has implemented a new attack strategy utilizing legitimate Windows tools to bypass security measures. The group’s latest technique involves Microsoft Application Virtualization Injector (MAVInject.exe) to inject malicious payloads into the waitfor.exe process.

Key Attack Components:
– Initial dropper: IRSetup.exe
– Legitimate Electronic Arts application (OriginLegacyCLI.exe)
– Modified TONESHELL backdoor (EACore.dll)
– Target focus: Thailand-based users

Attack Methodology:
1. Deployment of multiple files including decoy PDF documents
2. Utilization of Setup Factory for payload execution
3. Sideloading of malicious DLL through legitimate EA application
4. Process injection using MAVInject.exe
5. Command and control communication through militarytc[.]com:443

Southeast Asian Connection:
Recent investigations revealed infrastructure overlaps with Bookworm malware targeting ASEAN organizations. The attacks utilize:
– PUBLOAD downloader malware
– DLL side-loading techniques
– Shared code similarities between Bookworm and TONESHELL backdoor

ESET Response:
ESET has contested claims about their antivirus being bypassed, stating:
– The technique is not novel
– Existing protection against the reported method
– Prior detection capabilities implemented since January
– Attribution to China-aligned CeranaKeeper APT Group

The malware’s versatility and continuous evolution suggest potential future appearances in targeted attacks across Southeast Asia.

Share This Article