The CrowdStrike 2026 Technology Threat Landscape Report highlights that the technology sector remains the primary target for both state-sponsored and eCrime adversaries. China-nexus actors focus on intellectual property theft and AI capabilities, while DPRK-nexus actors leverage fraudulent employment and open-source supply chain compromises (such as the Axios npm package). Additionally, eCrime groups are accelerating extortion operations and exploiting AI trends to distribute malware like macOS infostealers.
Mustang Panda
6 posts
CrowdStrike 2026 Technology Threat Landscape Report: China’s Ambitions Fuel Attacks Converging Interests: Analysis of Threat Clusters Targeting a Southeast Asian Government Unit 42 identified a coordinated cyberespionage campaign targeting a Southeast Asian government entity, involving three distinct China-aligned threat clusters. The attackers utilized a variety of tools including USB worms, custom loaders, and multiple remote access Trojans (PUBLOAD, Masol, Gorem, FluffyGh0st) to establish persistent access, evade detection via DLL sideloading, and exfiltrate sensitive data.
EDR killers explained: Beyond the drivers Ransomware affiliates increasingly rely on EDR killers—ranging from BYOVD exploits and abused anti-rootkits to driverless tools—to disrupt security solutions prior to deploying encryptors. This approach allows encryptors to remain simple while the EDR killers handle complex defense evasion, complicating attribution and defense strategies.
China-nexus Group Targets Persian Gulf Region | ThreatLabz A China-nexus threat actor, assessed with medium confidence as Mustang Panda, targeted the Persian Gulf region using a multi-stage attack chain themed around the Middle East conflict. The campaign leverages LNK and CHM files to execute a heavily obfuscated shellcode loader via DLL sideloading, ultimately deploying a PlugX backdoor capable of HTTPS and DNS-over-HTTPS (DoH) C2 communications.
Middle East Conflict Fuels Cyber Attacks | ThreatLabz Threat actors are capitalizing on Middle East geopolitical tensions using over 8,000 newly registered domains to launch opportunistic cyber attacks. Campaigns include Mustang Panda deploying the LOTUSLITE backdoor via DLL sideloading, fake news sites distributing StealC malware, and various phishing/scam operations exhibiting Persian-language artifacts.
UNC6384 Weaponizes ZDI-CAN-25373 Vulnerability to Deploy PlugX Against Hungarian and Belgian Diplomatic Entities Arctic Wolf Labs has identified a cyber espionage campaign by the Chinese-affiliated threat actor UNC6384 targeting European diplomatic entities. The campaign exploits the ZDI-CAN-25373 Windows shortcut vulnerability to deliver malicious LNK files, ultimately deploying the PlugX RAT via DLL side-loading of legitimate Canon printer utilities.