Polaris is referenced in the provided content as part of reporting on the PRC-linked espionage actor Mustang Panda, also tracked as Hive0154, Stately Taurus, TA416, and BRONZE PRESIDENT. The content indicates this actor conducts cyber espionage and has targeted Southeast Asia, including Thailand and Myanmar, as well as diplomats, attendees of government-related events, European government organizations, Taiwanese government and diplomats, and some Russian-speaking targets. Reported malware and tooling associated with this activity include TONESHELL, SnakeDisk, PUBLOAD, PlugX/Korplug variants, DOPLUGS, Hodur, ShadowPad, Cobalt Strike, MQsTTang, Yokai, WavyExfiller, CeranaKeeper, STATICPLUGIN, FDMTP, MimiKatz, and RemCom. The reporting also describes a PRC-nexus campaign that hijacked web traffic to target diplomats. The content further notes continued evolution in tradecraft, including an updated TONESHELL backdoor, a novel USB-propagating worm called SnakeDisk, side-loading techniques involving Yokai, and campaigns such as SmugX. Based on the provided material, Polaris appears in the context of Mustang Panda-related research rather than as a clearly distinct actor.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
8 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 malware family attributed to this actor across reporting.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.