Researchers reported that the China-linked espionage group Mustang Panda (TA416, RedDelta, PKPLUG) has run a long-lived phishing campaign since at least August 2021 against European diplomatic missions, internet service providers, and research organizations, with many observed victims in Mongolia, Vietnam, and Myanmar and additional targeting in Europe and Africa. The lures used decoy documents tied to current events and government themes, including Ukraine border tensions, COVID-19 travel restrictions, and EU regulations, to entice targets into opening malicious files.
The intrusions delivered a previously undocumented Korplug/PlugX variant dubbed Hodur, continuing a pattern of Mustang Panda PlugX activity seen in earlier Exchange-related and Myanmar-focused operations. The infection chain commonly relied on DLL side-loading with legitimate signed executables such as SmadAV, a malicious loader, and an encrypted payload, sometimes preceded by a downloader fetching components over HTTPS. Analysts said the malware introduced stronger obfuscation, encrypted strings and payloads, anti-analysis features, registry or scheduled-task persistence, and encrypted command-and-control over HTTPS or custom TCP with RC4, enabling reconnaissance, file theft, remote shell access, and broader espionage operations.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
8 events from the most recent confirmed update back to the earliest known activity.
As of March 2022, ESET reported the campaign was still ongoing, identified a previously undocumented Korplug/PlugX variant it named Hodur, and attributed the operation with high confidence to Mustang Panda. ESET described the malware’s side-loading chain, anti-analysis features, persistence methods, and custom encrypted TCP command-and-control protocol.
ESET said the Mustang Panda cyberespionage campaign began at least in August 2021. The operation targeted research entities, internet service providers, and diplomatic missions across countries including Mongolia, Vietnam, Myanmar, Greece, Russia, Cyprus, South Sudan, South Africa, and others.
During the April 2021 wave, the malware created a scheduled task named MicrosoftCorp.xml and a Run key under HKCU\Software\Microsoft\Windows\CurrentVersion\Run\ACMguid. Its second stage connected to 65.21.111.255/maps/overlayBFPR and retrieved a Cobalt Strike beacon.
In the last week of April 2021, attackers sent a new malicious email to a mailing list with a Google Drive link to a RAR archive named "CEC List & CRPH (Meeting minutes).rar." The archive contained a legitimate executable and a malicious Acrobat.dll used for DLL side-loading.
On March 11, 2021, a malicious email was sent to a member of Myanmar’s Committee Representing Pyidaungsu Hluttaw. The message linked to a Google Drive-hosted RAR archive containing a malicious .lnk-based infection chain that abused SmadavProtect32.exe and SmadHook32c.dll for DLL side-loading.
In 2021, Unit 42 documented the previously unseen THOR PlugX variant. Later ESET reporting said Mustang Panda’s Hodur variant closely resembled THOR.
Qurium reported that command-and-control infrastructure later seen in the Myanmar phishing attacks had also been used in another targeted attack in December 2020 attributed to Mustang Panda.
During the ongoing campaign, Mustang Panda refreshed phishing lures to match current European events, including COVID-19 travel restrictions, EU regulations, and Russia’s invasion of Ukraine. Example lure names included "Situation at the EU borders with Ukraine.exe."
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
7 references tracked. Mallory keeps watching after this page renders.
welivesecurity.com
Open sourcebleepingcomputer.com
Open sourceunit42.paloaltonetworks.com
Open sourceblog.xorhex.com
Open sourcequrium.org
Open sourceavira.com
Open sourcewelivesecurity.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.