Researchers reported a suspected Mustang Panda intrusion campaign using politically themed lure files tied to Asian diplomatic relationships, including a shortcut file named 新段階に入った日印の戦略的関係.pdf.lnk that was believed to target Japan's Ministry of Foreign Affairs and Ministry of Defense. The lure referenced the deepening strategic relationship between Japan and India, aligning with the group's known interest in regional geopolitics and security cooperation such as the Quad.
A related analysis linked the activity to PulseRAT, a remote access trojan that used a UAE-India partnership lure and relied on Google Sheets for command-and-control functionality. Taken together, the reports indicate an espionage-focused operation using diplomatic and strategic partnership themes to socially engineer targets and deploy malware against government or policy-linked entities in Asia.

TTPs, infrastructure, and targeting history in one profile.
2 events from the most recent confirmed update back to the earliest known activity.
A malicious LNK file named "新段階に入った日印の戦略的関係.pdf.lnk" was assessed as likely targeting Japan's Ministry of Foreign Affairs and Ministry of Defense. The post describes the attribution to Mustang Panda as suspected rather than confirmed.
A PulseRAT remote access trojan campaign used a lure themed around the UAE-India partnership, according to the referenced analysis. The provided content does not explicitly anchor when the campaign occurred.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
2 references tracked. Mallory keeps watching after this page renders.
malware.news
Open sourcedmpdump.github.io
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.