China-linked espionage group Earth Preta—also tracked as Mustang Panda—updated its intrusion playbook to improve stealth, shifting from phishing emails with embedded malicious archives or direct cloud links to decoy documents that provide Google Drive links and passwords for protected archives. Those archives delivered malware including TONEINS, TONESHELL, and PUBLOAD, while follow-on activity used backdoors and loaders such as CLEXEC, COOLCLIENT, TROCLIENT, PlugX, and MQTT-based implants including QMAGENT/MQsTTang. Separate reporting tied Mustang Panda activity to targeted attacks in Asia, including Southeast Asia and likely Japan, where the group was also observed using malware such as Claimloader.
Researchers said the actor expanded its post-compromise toolkit with privilege-escalation and lateral-movement utilities including ABPASS, CCPASS, HIUPAN, ACNSHELL, and abuse of SilentCleanup for elevation. For data theft, the group relied on both legitimate tools such as WinRAR, curl, and FTP and custom packers NUPAKAGE and ZPAKAGE to collect and encrypt sensitive documents for exfiltration. Infrastructure overlaps, malware artifacts, and developer traces—including the name "TaoZongjie" and the GitHub account YanNaingOo0072022—were cited as links across the broader Earth Preta intrusion set, underscoring a sustained and adaptive regional cyber-espionage campaign.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
7 events from the most recent confirmed update back to the earliest known activity.
Beginning in June 2024, Earth Preta ran a fast-moving spear-phishing campaign against government-focused targets in the Asia-Pacific region using .url attachments that triggered a multi-stage infection chain. Trend Micro said the campaign used DOWNBAIT, PULLBAIT, CBROVER, and PLUGX, followed by file collection and possible exfiltration via Microsoft cloud and Graph API-related infrastructure.
Check Point Research reported a SmugX campaign in which Chinese threat actors targeted organizations in Europe. This introduces a distinct victim geography and campaign cluster not reflected in the existing timeline entries.
Trend Micro reported that a new PUBLOAD variant had been observed since October 2022. The variant used spoofed HTTP headers with legitimate-looking host names to conceal malicious traffic and supported data upload and command execution.
Beginning in October and November 2022, Earth Preta (Mustang Panda) changed its spear-phishing tradecraft to use decoy documents containing Google Drive links and passwords for malicious archives, delivering TONEINS, TONESHELL, and PUBLOAD. Trend Micro described this as a shift away from directly embedding malicious archives or Google Drive links in phishing emails.
On 2022-09-08, Secureworks published technical details and indicators for a BRONZE PRESIDENT (Mustang Panda) campaign targeting government and diplomatic officials with lure-themed RAR archives containing LNK files, side-loading DLLs, and encrypted PlugX payloads. The report also identified PlugX command-and-control infrastructure and multiple government-themed lures tied to the activity.
During 2022 and 2023, Earth Preta ran spear-phishing campaigns across multiple Asian countries using Google Drive links to password-protected archives with malicious LNK files that installed a customized PlugX downloader Trend Micro named DOPLUGS. The malware acted as a downloader and backdoor, and some variants were integrated with the KillSomeOne USB worm module for removable-media propagation and data theft.
Lab52 reported a Mustang Panda campaign targeting Taiwanese government entities and diplomats using a new PlugX variant. This represents a distinct victim focus and malware development not explicitly covered in the existing timeline.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
9 references tracked. Mallory keeps watching after this page renders.
trendmicro.com
Open sourcetrendmicro.com
Open sourceresearch.checkpoint.com
Open sourcetrendmicro.com
Open sourcemandiant.com
Open sourcelac.co.jp
Open sourcesecureworks.com
Open sourcelab52.io
Open sourcego.recordedfuture.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.