China-linked Mustang Panda continued deploying PlugX in espionage operations targeting government and diplomatic entities across Asia, with reporting tying activity to victims in Indonesia, Vietnam, Taiwan, and Japan. Researchers linked multiple intrusions to politically themed and administrative lures, including election-related documents, tax and education themes, and regional diplomatic topics. In Indonesia, PlugX command-and-control traffic was found on networks belonging to at least ten ministries and agencies, including the national intelligence service, while separate investigations described likely Mustang Panda activity against Vietnamese organizations and campaigns aimed at Taiwanese government officials and diplomats.
Across the cases, the group repeatedly used DLL sideloading, staged loaders, and obfuscated payloads to install PlugX in memory while maintaining persistence through Run registry keys and encrypted configuration data. Recent samples used lure archives, malicious LNK files, MSI packages, and decoy PDFs, then chained tools such as PowerShell, mshta, rundll32, and legitimate executables to sideload malicious DLLs and decrypt DAT payloads. Analysts also highlighted evolving tradecraft, including Nim- and Golang-based loaders, RC4 and XOR-based configuration protection, reflective loading, and time-restricted or rotating command-and-control infrastructure such as coastallasercompany.com, ivibers[.]com, meetvibersapi[.]com, and earlier temporally activated domains associated with prior PlugX campaigns.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
17 events from the most recent confirmed update back to the earliest known activity.
A lure archive named "Energy_Infrastructure_Situation_Note_Tehran_Province_2026.zip" tied to a Mustang Panda PlugX infection chain was first seen on 2026-03-17 05:42:13 UTC. The ZIP launched a hidden PowerShell loader that extracted and executed staged malware components.
Cyble reported a May 2024 campaign targeting Vietnamese entities with a malicious LNK disguised as a PDF. The chain used forfiles.exe, mshta, PowerShell, DLL sideloading via HP.exe and HPCustPartUI.dll, persistence, and beaconing to back.vlvlvlvl.site.
Cyble observed an April 2024 Mustang Panda campaign targeting Vietnamese entities using a ZIP archive named "huongdan memay.zip" containing a malicious LNK. The infection chain downloaded a lure document, collected host information, and exfiltrated it to megacybernews[.]com.
Lab52 analyzed a campaign targeting Taiwanese government entities and diplomats with a new PlugX variant linked through tradecraft similarities to SmugX and Mustang Panda. The lure document referenced Taiwan's January 2024 presidential election and the Terry Gou/Lai Peixia ticket.
VinCSS selected a log.dll sample for analysis after it was submitted to VirusTotal from Vietnam on 2022-04-25. The DLL read log.dat, decrypted shellcode, and ultimately loaded a PlugX variant in memory.
VinCSS analyzed a log.dat sample later tied to a Mustang Panda-linked PlugX infection chain that was submitted to VirusTotal on 2022-04-20. The file was the encrypted companion payload used by the loader DLL.
In a related late-April 2022 case, the same Japanese campaign infrastructure delivered an ISO file containing a decoy, a legitimate Microsoft Word executable, and a malicious sideloaded DLL. The Golang DLL downloader then retrieved and executed a Cobalt Strike stager.
Multiple Japanese organizations observed a targeted attack campaign in mid-April 2022 involving spear-phishing URLs, ZIP archives, malicious LNK files, decoy PDFs, and Word startup-template abuse. The campaign likely was also active in March 2022.
NTT Security reported that a highly similar LNK sample was uploaded from Japan to VirusTotal in March 2022. Although it used cmd.exe instead of ScriptRunner.exe, it shared overlapping commands and infrastructure with the later April campaign.
A sample sharing the unusual User-Agent characteristic later seen in the Japanese campaign was uploaded from Japan to VirusTotal in January 2022. NTT Security treated it as an early indicator linked to the same activity cluster.
NTT Security reported that the domain differentfor[.]com, later tied to overlapping infrastructure and malware characteristics in the Japanese campaign, was registered in November 2021. The domain shared file paths, HTTP headers, and Cobalt Strike configuration with later activity.
NTT Security found indications that a similar attack using related infrastructure may have occurred in late October 2021 against Japanese targets. A fake Sasakawa Peace Foundation website may have been used to distribute malicious files.
Insikt Group again notified Indonesian authorities in July 2021 after identifying the intrusion activity. According to the report, officials did not provide feedback.
Insikt Group notified Indonesian authorities about the Mustang Panda intrusions in June 2021. The notifications concerned compromises affecting multiple government ministries and agencies.
Insikt Group first discovered the Mustang Panda-linked intrusion affecting Indonesian government networks in April 2021. The finding was based on PlugX command-and-control servers communicating with hosts inside those networks.
Researchers traced PlugX command-and-control communications between Mustang Panda infrastructure and Indonesian government hosts back to at least March 2021. The affected entities included at least ten ministries and agencies, including BIN.
Lab52 detected a June 2020 malware sample that used a legitimate Adobe Suite binary to sideload a malicious DLL and deploy the PlugX trojan. The report assessed with high probability that the sample belonged to a new Mustang Panda campaign.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
9 references tracked. Mallory keeps watching after this page renders.
anomali.com
Open source0x3obad.github.io
Open sourcecyble.com
Open sourcelab52.io
Open sourceblog.vincss.net
Open sourceinsight-jp.nttsecurity.com
Open sourcetherecord.media
Open sourcelab52.io
Open sourceblog.quarkslab.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.