MQsTTang is a custom Windows backdoor used in espionage operations linked to the China-aligned intrusion set CeranaKeeper and previously attributed to Mustang Panda. First observed in campaigns traceable to early 2023, it is a relatively barebones, single-stage implant that provides remote shell functionality by executing arbitrary commands on an infected host and returning command output to the operator. Its most distinctive characteristic is command-and-control over MQTT, using a legitimate public broker to obscure attacker infrastructure and blend malicious traffic with benign messaging patterns.
The malware is built with the Qt framework and the QMQTT library. It generates a unique client identifier, connects to MQTT topics dedicated to operator-to-victim and victim-to-operator messaging, periodically sends keepalive data, and encodes message content before transmission. Later variants added anti-analysis logic that checks for common debugging and monitoring tools and alters topic usage when such tooling is detected, indicating active development focused on defense evasion.
MQsTTang establishes persistence by copying itself into a public user-accessible location and configuring automatic execution at user logon through a Run key. It does not rely on a complex multi-stage loader chain in the observed cases, distinguishing it from some other tooling associated with the same threat ecosystem. Delivery has been associated with archive files containing a single executable disguised with diplomatic or passport-themed lures, consistent with spearphishing operations targeting political and governmental entities.
Observed targeting has included governmental and politically relevant organizations in Europe and Asia, with indications of interest in foreign ministries, embassies, and Taiwan-related entities. Infrastructure and tradecraft overlap connect MQsTTang to a broader cluster that has also used other custom backdoors and espionage tooling. MQsTTang is best characterized as a lightweight command-execution backdoor designed for stealthy foothold maintenance and operator-driven post-compromise activity on Windows systems.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
There have only been a handful of instances reported, with the most recent being the MQsTTang backdoor attributed to the threat actor Mustang Panda.
ESET researchers have analyzed MQsTTang, a new custom backdoor... MQsTTang is a barebones backdoor that allows the attacker to execute arbitrary commands on a victim’s machine and get the output... its use of the MQTT protocol for C&C communication.
23 distinct techniques documented for this family, organized by ATT&CK tactic.
The backdoor ... are executables with names related to foreign affairs, such as PDF_ Contacts List Of Invitated Deplomatic Members and Note_Documents_No.14-Tokyo-__From___Embassy___of___Russia_ . ... samples also contain folder icon in an attempt to deceive victims about their real purpose.
Similar to MQsTTang, the TinyNote backdoor samples also contain folder icon in an attempt to deceive victims about their real purpose.
“the registry key is created with the name qvlc. This matches the name of a legitimate executable used by VLC.”
“When creating copies, MQsTTang uses filenames of legitimate programs.”
The malware samples also communicate with other known C&C servers... constructs a GET request: http://5.188.33.190/api.php ... The encoded enumeration data is stored in a cookie called SSN ... expected result ... JSON ... {"msg":"[BASE64-ENCODED COMMAND]"}
This backdoor is unique because it communicates to its C&C servers over the MQTT protocol
“MQsTTang uses a legitimate public MQTT broker… broker.emqx.io”
1 indicator attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A custom backdoor used by Mustang Panda for espionage and persistent access.
A backdoor noted as another example of malware using MQTT for command-and-control communications.
MQsTTang (QMAGENT) is a backdoor developed by Mustang Panda for espionage and persistent access.
Backdoor associated with the same espionage activity cluster; referenced as sharing infrastructure/victimology with TinyNote and using overlapping delivery/C2 servers.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.