Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
36 distinct techniques documented for this family, organized by ATT&CK tactic.
Mustang Panda: “Execution T1053.005 … Scheduled Task” and “Persistence T1053.005 … Scheduled Task”. Ripper narrative: “maintains long-term presence… by creating and modifying Windows scheduled tasks… run with SYSTEM-level privileges”.
Mustang Panda: “Execution T1053.005 … Scheduled Task” and “Persistence T1053.005 … Scheduled Task”. Ripper narrative: “maintains long-term presence… by creating and modifying Windows scheduled tasks… run with SYSTEM-level privileges”.
Ripper: “Persistence T1112 Modify Registry” and “Defense Evasion T1112 Modify Registry”.
Mustang Panda: “Execution T1053.005 … Scheduled Task” and “Persistence T1053.005 … Scheduled Task”. Ripper narrative: “maintains long-term presence… by creating and modifying Windows scheduled tasks… run with SYSTEM-level privileges”.
Ripper: “Privilege Escalation T1055 Process Injection” and “Defense Evasion T1055 Process Injection”.
Ripper: “Defense Evasion T1014 Rootkit”. Mustang Panda narrative: “kernel-mode… mini-filter driver… rootkit-level protections… disrupts Microsoft Defender’s file system filtering.”
Ripper: “Defense Evasion T1027.005 … Indicator Removal from Tools”.
Ripper: “Defense Evasion T1036 Masquerading”. Mustang Panda: multiple masquerading sub-techniques (T1036.004/.005/.007).
Ripper: “Privilege Escalation T1055 Process Injection” and “Defense Evasion T1055 Process Injection”.
Ripper: “Defense Evasion T1070.004 … File Deletion”. Mustang Panda: same technique listed.
Ripper: listed under Privilege Escalation and Defense Evasion as “Access Token Manipulation: Parent PID Spoofing”.
Ripper: “Defense Evasion T1140 Deobfuscate/Decode Files or Information”.
Ripper: listed under Defense Evasion and Discovery. Kimwolf (mobile): “T1633 Virtualization/Sandbox Evasion”.
Ripper: “Discovery T1016 System Network Configuration Discovery”. Mustang Panda: same technique listed.
Ripper: “Discovery T1082 System Information Discovery”. Mustang Panda: same technique listed.
Ripper: “Discovery T1083 File and Directory Discovery”. Mustang Panda: same technique listed.
Ripper: listed under Defense Evasion and Discovery. Kimwolf (mobile): “T1633 Virtualization/Sandbox Evasion”.
Ripper: “Command and Control T1071 Application Layer Protocol”. Kimwolf (mobile): “T1437 Application Layer Protocol”. Mustang Panda: “T1071.001 … Web Protocols”.
Ripper: “Command and Control T1095 Non-Application Layer Protocol”. Mustang Panda: same technique listed; narrative mentions raw TCP on 443 with fake TLS 1.3 headers.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.