Automatically translated.View original post

Mustang Panda Revisited Malware Upgrade

Mustang Panda Revisited Upgraded CoolClient Malware to Steal Browser Login

The name of Mustang Panda or HoneyMyte may be familiar to cybersecurity followers, because over the past year, a group of hackers have attacked Thai government agencies with malware that, once embedded into the system, can spread through a USB drive, and this time the hackers have returned.

According to a report by the website Cyber Press, it discusses the return of hackers from China, Mustang Panda, in late 2025, along with the upgrading of CoolClient malware, a type of system back door or backdoor malware, with new features that make it easier to steal login data from web browsers. Of course, this group of hackers continues to focus its attacks on Southeast Asian countries such as Myanmar, Malaysia and Thailand. It also attacks other countries such as Mongolia, Pakistan, and Russia.

CoolClient malware is not new because it has been detected since 2022, according to Sophos, a company that develops anti-malware tools for enterprises, and has been confirmed by Trend Micro, another anti-malware developer, that the malware exists. During that time, the malware served as a secondary backdoor to PlugX and LuminousMoth malware.

To send this malware into the victim's machine, hackers originally used Shellcode-encrypted loader and malware DLL files as a malware transmitter by luring properly-signed applications such as BitDefender, VLC, Ulead PhotoImpact, and Sangfor as a malware DLL loader. This is a method of attack called DLL Sideloading. For the latest version, the malware uses Sangfor's Sang.exe to load a DLL file called libngs.dll. By loading it, it leads to decryption. (Decoding) The settings files of the malware are named loader.dat and time.dat.

From that step it leads to the implementation of 3 Param parameters (except for the first that is not the implementation of Param), i.e.

No param to lead to "Trigger" Install (install malware)

Install leads to Run Key, creates a write.exe file, shoots the script from loader.dat, sets up a Service called media _ updaten, checks if there is an anti-virus such as 360sd.exe running on the machine)

Work, this Param will be shot into a process called write.exe

Passuac will perform Bypass, UAC (User Account Control), Fake (Spoof) Process svchost PEB, and add a task called ComboxResetTask.

And finally, it loads DLL files inside main.dat, which have a variety of malware capabilities, such as

It stores information about the victim's system, such as the name of the machine, the operating system, and specifications.

Ability to upload and delete files on the machine

TCP Tunneling Implementation

Plug-In implementation of malware

Proxy Reverse Implementation

Keylogging

In addition, in the latest version of the malware, various capabilities have been added, such as

Data observation on ClipBoard with the implementation of the GetClipboardData / GetWindowTextW command and then using XOR-based encoding to C: ProgramDataAppxProvisioning xml

Tracking various Window activations

Data capture via HTTP protocol with HTTP Proxy Sniffer method

The malware, in addition to the early malware capabilities, has three plug-ins:

FileMgrS.dll for managing files on the machine (File Ops)

ServiceMgrS.dll is used to manage various services on board, covering both enum / start / stop / create.

RemoteShellS.dll used to hide cmd.exe with Pipe I / O

Not only that, the malware is also paired (Pair), the malware, together with the web browser data theft malware (Browser Stealer), covering a variety of browsers, e.g.

Chrome, MD5: 1A5A9C013CE1B65ABC75D809A25D36A7

Edge, E1B7EF0F3AC0A0A64F86E220F362B149

Chromium, DA6F89F15094FD3F74BA186954BE6B05

# Trending # Lemon 8 Howtoo # lemon 8 diary # freedomhack # Malware

2/27 Edited to

... Read moreจากประสบการณ์ของผู้ที่ทำงานด้านความปลอดภัยไซเบอร์ การติดตามพฤติกรรมของกลุ่ม Mustang Panda หรือ HoneyMyte นี้มีความสำคัญอย่างยิ่ง เพราะพวกเขามีเทคนิคที่พัฒนาตลอดเวลาเพื่อหลบเลี่ยงระบบตรวจจับ มัลแวร์ CoolClient เป็นตัวอย่างที่ดีของมัลแวร์ประเภท backdoor ที่ถูกฝังในระบบอย่างแนบเนียน โดยเฉพาะอย่างยิ่งการใช้วิธี DLL sideloading ผ่านโปรแกรมที่ได้รับการรับรองอย่าง BitDefender, VLC, Ulead PhotoImpact ซึ่งทำให้มัลแวร์ดูเหมือนเป็นไฟล์ปกติและรันได้โดยไม่มีข้อสงสัย การเข้ารหัสด้วย shellcode และการใช้ไฟล์ DLL อย่าง libngs.dll ที่ถูกโหลดโดย Sang.exe นั้นช่วยหลบเลี่ยงการตรวจจับและรันคำสั่งติดตั้งมัลแวร์อย่างเงียบ ๆ เทคนิคการใช้พารามิเตอร์ที่หลากหลาย เช่น การติดตั้งตัวมัลแวร์, การหลบเลี่ยง UAC, ปลอมแปลง process svchost และสร้าง task ใหม่ ช่วยให้มัลแวร์ทำงานได้ต่อเนื่องและซ่อนตัวได้ดีขึ้น นอกจากนี้ ฟีเจอร์ใหม่อย่างการดักจับ clipboard และ HTTP Proxy Sniffer ทำให้มัลแวร์สามารถขโมยข้อมูลได้หลากหลายช่องทาง รวมถึงการจับคู่มัลแวร์ขโมยล็อกอินบนเบราว์เซอร์ต่าง ๆ เช่น Chrome, Edge และ Chromium เป็นตัวเพิ่มศักยภาพการขโมยข้อมูลส่วนตัวของเป้าหมาย จากข้อเท็จจริงนี้ ผู้ดูแลระบบและผู้ใช้งานทั่วไปควรตระหนักถึงความเสี่ยงโดยติดตั้งโปรแกรมป้องกันมัลแวร์ที่อัปเดตล่าสุด และหลีกเลี่ยงการเปิดไฟล์หรือโปรแกรมจากแหล่งที่ไม่เชื่อถือ โดยเฉพาะไฟล์ที่ถูกส่งผ่านทางอีเมลหรือ USB นอกจากนี้ การเฝ้าระวังพฤติกรรมที่ผิดปกติของระบบ และการตั้งค่าความปลอดภัยเบราว์เซอร์ให้เหมาะสมจะช่วยลดความเสี่ยงจากการโดนขโมยข้อมูลล็อกอินได้อีกทางหนึ่ง ในสายงานนี้ ผมเคยพบหลายครั้งที่มัลแวร์ประเภท backdoor แบบนี้ถูกใช้แทรกซึมเข้าสู่ระบบราชการหรือองค์กรธุรกิจ ทำให้เกิดความเสียหายทั้งข้อมูลและความน่าเชื่อถือขององค์กร การรู้จักเทคนิคและความสามารถของมัลแวร์ CoolClient รวมถึงการอัปเกรดล่าสุด จะช่วยให้เราสามารถเตรียมตัวรับมือและพัฒนากลยุทธ์ในการป้องกันที่มีประสิทธิภาพได้

Related posts

Mermaid Shell Tile Tutorial 🧜‍♀️
Love how this turns out! I used this technique over a year ago and finally revisited it :) I messed up plenty of times following my own tutorial 😅 so take your time with this one. Hope it helps! #ohuhu #cocowyo #colorwithme #coloringtutorial #coloring
Cozy’s Coloring Nook

Cozy’s Coloring Nook

30 likes

My essay speedrun hacks 📝🌟
Hey, I never said it would be easy lol. This is how I write my essays when i’m on a time crunch and make sure they’re still good quality: Day 1 I usually dedicate this first day on writing a thorough outline. This depends a lot on what your rubric is asking for, so make note of that as well as
natalie

natalie

2312 likes

Sasquatch Revisited Dowsing Rod Q&A
Sasquatch Revisited Dowsing Rod Q&A I have gotten a TON of feedback from the Sasquatch community, so I decided to revisit this topic. Looks like Sasquatch are real in spirit form! Do you agree with the dowsing rods? Let me know your thoughts in the comments! 👇 #sasquach #bigfoot
Rachel.lannyy

Rachel.lannyy

12 likes

Cardio,abz,obliquez!#GOON4LIFE! 💯!
GOON4LIFE(Revisited)

GOON4LIFE(Revisited)

26 likes

Morbius Revisited #2 Marvel Comic Book
Morbius Revisited 2 Marvel Comic Book for Sale at www.kevinsattic.com #Marvel #Comic #comicbooks #morbius #vampire
Kevin's Comics

Kevin's Comics

4 likes

Autistic & Female Ozzy
#musictherapy #ozzyosbourne #fyp #rocknroll #differentnotless Let There Be Rock School WV
Tori

Tori

11 likes

1861 Revisited by James E. Roethlein
James E. Roethlein poet

James E. Roethlein poet

13 likes

I went back to the cat cafe!! . . . #cat #solo #pov
bengtalks

bengtalks

58 likes

It’s Beyond Jazz Infinite Gems

It’s Beyond Jazz Infinite Gems

3 likes

When the Moon moves through Libra, emotional awareness often turns toward relationships. You may notice yourself thinking more about fairness, balance, and how you and others are showing up for each other. With Mercury retrograde at the same time, communication may require extra patience.
energysrce

energysrce

1 like

GNE #9
Game Night Revisited… decided to add subs to an #onthisday from 2022. Let’s Play! #gamenightexcuses
Capt. Shinbones

Capt. Shinbones

0 likes

A Teaser of One of Our Short Dance Films
Temper Tantrum

Temper Tantrum

2 likes

my bio notes (pt. 1) 📑🧬✨
my bio notes (pt. 1) topics covered: - neurons - action potentials this is a topic that is constantly revisited in other classes (so far i’ve had it come up in my chem, anatomy, and psych classes) so definitely try and get it down pat! recreating diagrams and creating scenarios helped me th
lia 💗

lia 💗

338 likes

Legz,back,abz,obliquez!! #GOON4LIFE! GOOD MORNING
GOON4LIFE(Revisited)

GOON4LIFE(Revisited)

29 likes

Armz,deltz,abz,obliquez!!GOON4LIFE! 💯
GOON4LIFE(Revisited)

GOON4LIFE(Revisited)

114 likes

That competitive edge you want is in a book 📚
8 books that stay on rotation and helped me change my mental outlook on different areas of life: 1. “Financial Peace Revisited” by Dave Ramsey Helped me manage my finances better 💵 2. “Can’t Hurt Me” by David Goggins Basically kicked my butt and told me the excuses I was making didn’t matte
Simone DuPree

Simone DuPree

31 likes

Chest,Shoulderz,abz, obliquez!! #GOON4LIFE!! 💯
GOON4LIFE(Revisited)

GOON4LIFE(Revisited)

43 likes

Chest,Shoulderz,abz,obliquez!! 💯#GOON4LIFE
GOON4LIFE(Revisited)

GOON4LIFE(Revisited)

27 likes

⚡ How to Make Your PC Run Faster – 5 Easy Tips! 🖥️🔥
💡 1. Disable Startup Programs 🚀 Too many apps launching at startup slow down your PC! ✅ Open Task Manager (Ctrl + Shift + Esc) ✅ Go to the Startup tab ✅ Disable unnecessary apps to speed up boot time 💡 2. Clean Temporary Files 🗑️ Over time, junk files slow your system down. ✅ Press Win
skaeszun

skaeszun

284 likes

Both start with a spark. Choose wisely #fyp #single #love #dating #relationships
stayforthestories

stayforthestories

0 likes

The Complete Smartist Guide The E Myth Mind Your Business workbook #artbiz #artistoftiktok
Nikki Paintz

Nikki Paintz

0 likes

Best scents that make people turn heads 😩
These were some of the perfumes I’ve bought over the past year. They make me genuinely feel so nice and smell nice, I hate floral smells but the ones I’ve added here I LOVE. They’re not too strong which I hate in floral smells, while also capturing the best light smells. #smellgoodfeelgood #s
Hanbyul Cho

Hanbyul Cho

1992 likes

5 of the best business books that ive ever read
5 of the best business books that ive ever read! One of my favorite non-fiction genres is business Here are 5 books worth reading if you're interested in entrepreneurship and startups, or want to live that digital-nomad life! 1. Good to Great > outlines how companies can transition f
BATE by Rana

BATE by Rana

156 likes

How to Find Your Deity Revisited!
On my post a WHILE ago a lot of people were confused as to which card represented each deity. Hopefully this graph I made helps! There are many deities that are NOT stated in this and I simply couldn't add them all either. Also, something else that I did not mention, and that other post is
𝙲𝚑𝚎𝚕𝚜𝚎𝚢◡̈

𝙲𝚑𝚎𝚕𝚜𝚎𝚢◡̈

1831 likes

The Angry Birds! Lulu battles an angry turkey!
#angrybirds #lol #funnylemon8 #luluvetter #viralreels
RJOHagan324/Lulu

RJOHagan324/Lulu

3 likes

💚🖤 #fyp #fypシ #fypシ゚viral #foryoupage #inspire #in
💚🖤 #fyp #fypシ #fypシ゚viral #foryoupage #inspire #inspiration #goviral #motivation #motivate #dankvisionz
Lisa Marie 💚🖤

Lisa Marie 💚🖤

6 likes

#GOON4LIFE! Legz,back,abz,obliquez!! 💯!!
GOON4LIFE(Revisited)

GOON4LIFE(Revisited)

86 likes

Unexpectedly single…💔 & not yet ready to mingle 🫶✨
I wasn’t sure if I should even go there & share anything about my recent breakup experience, or how it seemed to come out of nowhere…but I saw the #safespace 🍋8 challenge, and I knew it was time to let it out, at least a little. The back story 📖: Was in a relationship for 6 months in 2021
Renée Boettner

Renée Boettner

8 likes

Writing my heart out. He was an infant when he was injured. He wasn't going to have a normal life, but he was going to live. Everyday? that's all that matters. Now he has a voice. Purchased from: ISBN13 9798245690704
pnw.author.michelle.m

pnw.author.michelle.m

0 likes

#GOON4LIFE! Cardio,abz,obliquez!! GAMETIME! 💯
GOON4LIFE(Revisited)

GOON4LIFE(Revisited)

15 likes

Cardio,abz,obliquez!!# GOON4LIFE!! 💯
GOON4LIFE(Revisited)

GOON4LIFE(Revisited)

7 likes

study with me and snoopy 💗
study with me and snoopy 💗 hello friends! hope you are well :) i got a package from peanuts the other day with these cute snoopy plushies!! anyone who knows me knows i love the whole franchise so i was VERY excited to receive this. it inspired me to do a study with me post and create a snoop
lia 💗

lia 💗

106 likes

Preppy Revisited!
This outfit is a fun compilation of “me”. I rented these jeans, my son left this shirt in his closet when he moved out (I bought it for him years ago and it still had the H&M tags on it!) @walmart loafers, @target tie belt, @erinmcdermott1 necklace and @cosmoandclove earrings! Budget friendly
Suzi Wurzbach

Suzi Wurzbach

3 likes

This week’s lesson is focusing on the word, responsible and what it means to be responsible. We discuss what being responsible looks like both at home and at school. We also revisited the word empathy.
Counselor’s Corner

Counselor’s Corner

0 likes

Smell Expensive ✨
I first smelled Grand Soir years ago & it just wasn't for me. At the time it felt too grown, too heavy, & I didn't have the nose for amber like I do now. But once I got deeper into niche perfumery & started paying attention to how a fragrance unfolds on skin, my taste shifted a
Kat - Fragrance Fashion Beauty

Kat - Fragrance Fashion Beauty

2 likes

Indiana Mish (meesh)

Indiana Mish (meesh)

0 likes

The Twilight Zone - Deaths-Head Revisited S3. E9.
#deathsheadrevisited #thetwilightzone #twilightzone #rodserling #oldhollywood
FRED SIMMONS

FRED SIMMONS

2 likes

#asmr #tbr #emoji #game 360 #books now with #ambientnoise
Lea (rhymes with see)

Lea (rhymes with see)

0 likes

Cozy Game revisited
I've played this game once before. And it has been out for a while , but I feel like this game is underrated. It has a lot to do and is pretty good storywise #cozygaming #cozy #cozygames #STEAM #desksetup #deskspace #gaming #cutegames
Pocketsofcozy

Pocketsofcozy

16 likes

Awkward Question 37 Revisited!!!
Call it like you see it!!! 😜🤣🤣 #uploadsoffun #comedyvideo #funny #throwback #nicknames
Uploads of Fun

Uploads of Fun

146 likes

Awkward Question 85 Revisited!!!
Some things never change!!! 😜🤣🤣 #uploadsoffun #comedyvideo #funny #throwback
Uploads of Fun

Uploads of Fun

139 likes

Full Bottle or Forget It? Lattafa Pride Minis🔥🤔💭
Lattafa Pride Mini Set There were three I was the most excited to try: Eternal Oud, Artisan Ethnique, and Ishq Al Shuyukh Gold. I figured grabbing the mini set first was the smartest move just in case I didn’t end up loving one of them. The photo is arranged from my most favorite to least favor
egypt4goddess

egypt4goddess

20 likes

Box Jurassic Themed
I revisited an old friend I never got the chance to complete. I finally finished this box after it sitting for 3 yrs. I hope you all enjoy! what should I use it for? #box #painting #jurassicworld #jurassic #lava
Emily Stewart

Emily Stewart

2 likes

Shelfie 📚🕯️
There is nothing better than a well loved bookshelf, soft candlelight, and stories waiting to be revisited. Read Responsibly 🍷📚 #lemon8bookworm #lemon8bookclub #shelfie #readersoflemon8 #readingaesthetic
LilReadBookWyrm

LilReadBookWyrm

1 like

Awkward Question 71 Revisited!!!
This throwback is magical!!! 😜🤣🤣 #uploadsoffun #comedyvideo #funny
Uploads of Fun

Uploads of Fun

171 likes

Awkward Question 84 Revisited!!!
A delicious throwback!!! 😜🤣🤣 #uploadsoffun #comedyvideo #funny #throwback
Uploads of Fun

Uploads of Fun

155 likes

ACOTAR reread on vacation ☀️
me: goes on a summer vacation in the desert to get some sun also me: hides inside and reads all week long 📖☀️ I haven’t read the ACOTAR series again since the first time I picked it up two years ago, and I figured it was about time I revisited one of my very favorite stories. 🤍 this reread rea
Sarah Jean ✨

Sarah Jean ✨

7 likes

#GOON4LIFE ! Chest,shoulderz,abz,obliquez!! ALWAYZ 💯!
GOON4LIFE(Revisited)

GOON4LIFE(Revisited)

11 likes

See more