StarProxy is a Windows post-compromise proxying utility associated with the China-linked espionage group Mustang Panda. It is used to relay attacker communications through compromised hosts, enabling access to internal systems that are not directly exposed to the internet and supporting lateral movement within victim networks. The tool has been described as complementing the TONESHELL malware family in intrusions targeting organizations such as governments, military entities, NGOs, telecommunications, and think tanks, particularly in East Asia, Myanmar, and parts of Europe.
StarProxy is commonly executed through DLL side-loading using legitimate signed software, including observed use with IsoBurner. It accepts command-line parameters for network communication and uses Windows APIs during execution. Its core function is to proxy traffic between infected devices and command-and-control infrastructure. StarProxy supports both TCP and UDP in code, although reported samples were hardcoded for TCP in observed operations.
A notable feature of StarProxy is its use of FakeTLS to disguise command-and-control traffic. It crafts network traffic with TLS-like record headers to impersonate legitimate TLS versions, helping communications blend with normal encrypted traffic and complicating inspection. Reported implementations also used custom XOR-based protection for exchanged data. These behaviors indicate a design focused on stealthy internal pivoting, operational security, and maintaining communications across segmented networks.
At high confidence, StarProxy is best characterized as a proxying backdoor-style utility used after initial compromise rather than as an initial access payload. Its documented behavior centers on covert communications, internal traffic relaying, command execution via the command line, and support for attacker movement and post-exploitation activity inside compromised Windows environments.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Details on Exploited Vulnerabilities ... CVE-2021-40444 Microsoft Windows ... YARA Rules ... reference = “... PrintNightmare and MSHTML exploits” ... $cve2 = “CVE-2021-40444”
Details on Exploited Vulnerabilities ... CVE-2021-1675 Microsoft Windows ... YARA Rules ... reference = “... PrintNightmare and MSHTML exploits” ... $cve1 = “CVE-2021-1675”
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
A new piece of software associated with Mustang Panda is StarProxy ... designed to take advantage of FakeTLS protocol to proxy traffic and facilitate attacker communications.
12 distinct techniques documented for this family, organized by ATT&CK tactic.
APT19 downloaded and launched code within a SCT file; APT32 used COM scriptlets to download Cobalt Strike beacons; APT37 used Ruby scripts to execute payloads; ArcaneDoor included the adversary executing command line interface (CLI) commands.
The content repeatedly describes malware and threat actors decoding, decrypting, or deobfuscating payloads, strings, configuration data, commands, and C2 traffic prior to execution or use, e.g., 'APT28 macro uses the command certutil -decode to decode contents of a .txt file storing the base64 encoded payload' and 'Action RAT can use Base64 to decode actor-controlled C2 server communications.'
16 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Proxy/backdoor tooling referenced as part of Mustang Panda’s modular malware set (specific capabilities not detailed in the content).
... StarProxy ... (v1.0) ...
StarProxy (v1.0)
A lateral movement and proxy tool used by Mustang Panda to facilitate internal network access and traffic proxying, employing FakeTLS for stealthy communications and delivered via DLL sideloading.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.