MQsTTang is a custom, single-stage Windows backdoor observed in campaigns beginning in January 2023. Initially attributed to Mustang Panda, it was reassigned by ESET to CeranaKeeper in July 2025 following refinements to threat-group definitions and analysis of operational links. Observed activity included victims in Bulgaria and Australia and targeting of a governmental institution in Taiwan. The malware has been distributed in RAR archives containing a single executable disguised through diplomacy- and passport-themed names.
MQsTTang executes arbitrary commands and returns their standard output to its operators. It uses the MQTT publish-subscribe protocol for command-and-control through a legitimate public broker, separating infected hosts from direct connections to attacker infrastructure. Its implementation uses the open-source QMQTT library and statically linked portions of the Qt framework. Messages are encoded using Base64 and XOR, and periodic keepalive messages report uptime. The backdoor establishes persistence through a per-user Windows Run entry. Later versions detect common debuggers and monitoring tools by enumerating processes and checking window classes, then alter their MQTT communication topics when analysis tools are detected. Unlike the multistage loading chains historically associated with Mustang Panda, MQsTTang has a comparatively simple architecture without code obfuscation.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Malware used by Mustang Panda Horse Shell, WispRider, PlugX and Poison Ivy, DOPLUGS, MQsTTang, MirrorFace, Sogu
ESET researchers have analyzed MQsTTang, a new custom backdoor... MQsTTang is a barebones backdoor that allows the attacker to execute arbitrary commands on a victim’s machine and get the output... its use of the MQTT protocol for C&C communication.
23 distinct techniques documented for this family, organized by ATT&CK tactic.
The backdoor ... are executables with names related to foreign affairs, such as PDF_ Contacts List Of Invitated Deplomatic Members and Note_Documents_No.14-Tokyo-__From___Embassy___of___Russia_ . ... samples also contain folder icon in an attempt to deceive victims about their real purpose.
Similar to MQsTTang, the TinyNote backdoor samples also contain folder icon in an attempt to deceive victims about their real purpose.
“the registry key is created with the name qvlc. This matches the name of a legitimate executable used by VLC.”
“When creating copies, MQsTTang uses filenames of legitimate programs.”
BambooToken го користи протоколот Message Queuing Telemetry Transport (MQTT) како комуникациски канал за контрола на Windows и Linux системи... се влегува во команден циклус што користи MQTT за C2 комуникација.
The malware samples also communicate with other known C&C servers... constructs a GET request: http://5.188.33.190/api.php ... The encoded enumeration data is stored in a cookie called SSN ... expected result ... JSON ... {"msg":"[BASE64-ENCODED COMMAND]"}
This backdoor is unique because it communicates to its C&C servers over the MQTT protocol
“MQsTTang uses a legitimate public MQTT broker… broker.emqx.io”
1 indicator attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
8 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A Mustang Panda backdoor that uses MQTT/IoT messaging infrastructure for command-and-control and execution of commands on compromised systems.
An unrelated backdoor mentioned solely as a prior example of malware using MQTT; no further capabilities or campaign details are provided.
A custom backdoor used by Mustang Panda for espionage and persistent access.
Listed as malware used by Mustang Panda. Its capabilities and specific campaign involvement are not described.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.