{"id":3764,"date":"2021-09-24T15:59:46","date_gmt":"2021-09-24T20:59:46","guid":{"rendered":"https:\/\/truxgoservers.com\/blog\/?p=3764"},"modified":"2021-09-24T15:59:47","modified_gmt":"2021-09-24T20:59:47","slug":"mustang-panda-group-that-attacks-goverment-entities","status":"publish","type":"post","link":"https:\/\/truxgoservers.com\/blog\/mustang-panda-group-that-attacks-goverment-entities\/","title":{"rendered":"Mustang Panda group that attacks goverment entities"},"content":{"rendered":"\n<p>An Advanced Persistent Group that has been active for several years, HoneyMyte, also known as Mustang Panda, has adopted different techniques to carry out attacks in recent years and has focused on various targeting profiles. A recent report by cybersecurity firm Kaspersky released last July revealed that a group of activities has carried out cyber espionage attacks against government entities in Myanmar and the Philippines since at least October 2020. While they initially focused their attention on Myanmar, threat actors have shifted their focus to the Philippines. They usually get an initial foothold in the system via spear-phishing emails with a Dropbox download link.<\/p>\n\n\n\n<p>Once clicked, this link downloads a RAR file disguised as a Word document that contains a malicious payload. Once downloaded onto the system, the malware attempts to infect other hosts by spreading via removable USB drives. If the drive is found, the malware creates a hidden directory on the drive, where it then moves all of the victim&#8217;s files, along with the malicious executable. Kaspersky experts attribute this activity called LuminousMoth, which is closely related to the HoneyMyte threat group, a well-known, long-standing Chinese-language threat actor with moderate to high confidence.<\/p>\n\n\n\n<p>HoneyMyte is primarily interested in collecting geopolitical and economic intelligence in Asia and Africa. For example, in a previous attack carried out since mid-2018, this threat actor used PlugX implants, as well as a multi-stage PowerShell script similar to CobaltStrike. The campaign targets government entities in Myanmar, Mongolia, Ethiopia, Vietnam, and Bangladesh.<\/p>\n\n\n\n<p>The best thing to do against Mustang Panda or these kinds of threats is to provide your staff with basic cybersecurity training, as many targeted attacks start with phishing or other social engineering techniques Perform cybersecurity audits of your network and fix any vulnerabilities that are found at the perimeter or within the network. Installs anti-APT and EDR solutions, enabling timely threat discovery and detection, investigation, and incident remediation capabilities.<\/p>\n\n\n\n<p>More reads:<br><a href=\"https:\/\/truxgoservers.com\/blog\/ghostemperor-group-that-targets-high-profile-users\/\">GhostEmperor group that targets high profile users<\/a><br><a href=\"https:\/\/truxgoservers.com\/blog\/strongpity-an-infamous-group-of-cybercriminals\/\">StrongPity infamous group of cybercriminals<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>An Advanced Persistent Group that has been active for several years, HoneyMyte, also known as Mustang Panda, has adopted different techniques to carry out attacks in recent years and has focused on various targeting profiles. A recent report by cybersecurity firm Kaspersky released last July revealed that a group of activities has carried out cyber [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":3765,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[10],"tags":[36],"class_list":["post-3764","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cybersecurity","tag-cybersecurity"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.4 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Mustang Panda group that attacks goverment entities - Truxgo Server Blog<\/title>\n<meta name=\"description\" content=\"There are many groups of cybercriminals that are active, but today we will see a group known&#039;s as Mustang Panda.........\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/truxgoservers.com\/blog\/mustang-panda-group-that-attacks-goverment-entities\/\" \/>\n<meta property=\"og:locale\" content=\"es_MX\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Mustang Panda group that attacks goverment entities - Truxgo Server Blog\" \/>\n<meta property=\"og:description\" content=\"There are many groups of cybercriminals that are active, but today we will see a group known&#039;s as Mustang Panda.........\" \/>\n<meta property=\"og:url\" content=\"https:\/\/truxgoservers.com\/blog\/mustang-panda-group-that-attacks-goverment-entities\/\" \/>\n<meta property=\"og:site_name\" content=\"Truxgo Server Blog\" \/>\n<meta property=\"article:published_time\" content=\"2021-09-24T20:59:46+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2021-09-24T20:59:47+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2021\/09\/New-scaled.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"2560\" \/>\n\t<meta property=\"og:image:height\" content=\"1133\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"Truxgo\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Escrito por\" \/>\n\t<meta name=\"twitter:data1\" content=\"Truxgo\" \/>\n\t<meta name=\"twitter:label2\" content=\"Tiempo de lectura\" \/>\n\t<meta name=\"twitter:data2\" content=\"2 minutos\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/mustang-panda-group-that-attacks-goverment-entities\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/mustang-panda-group-that-attacks-goverment-entities\\\/\"},\"author\":{\"name\":\"Truxgo\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#\\\/schema\\\/person\\\/8b409c26449db6aa09724b45331e333e\"},\"headline\":\"Mustang Panda group that attacks goverment entities\",\"datePublished\":\"2021-09-24T20:59:46+00:00\",\"dateModified\":\"2021-09-24T20:59:47+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/mustang-panda-group-that-attacks-goverment-entities\\\/\"},\"wordCount\":338,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/mustang-panda-group-that-attacks-goverment-entities\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wp-content\\\/uploads\\\/2021\\\/09\\\/New-scaled.jpg\",\"keywords\":[\"Cybersecurity\"],\"articleSection\":[\"Cybersecurity\"],\"inLanguage\":\"es\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/mustang-panda-group-that-attacks-goverment-entities\\\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/mustang-panda-group-that-attacks-goverment-entities\\\/\",\"url\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/mustang-panda-group-that-attacks-goverment-entities\\\/\",\"name\":\"Mustang Panda group that attacks goverment entities - Truxgo Server Blog\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/mustang-panda-group-that-attacks-goverment-entities\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/mustang-panda-group-that-attacks-goverment-entities\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wp-content\\\/uploads\\\/2021\\\/09\\\/New-scaled.jpg\",\"datePublished\":\"2021-09-24T20:59:46+00:00\",\"dateModified\":\"2021-09-24T20:59:47+00:00\",\"description\":\"There are many groups of cybercriminals that are active, but today we will see a group known's as Mustang Panda.........\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/mustang-panda-group-that-attacks-goverment-entities\\\/#breadcrumb\"},\"inLanguage\":\"es\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/mustang-panda-group-that-attacks-goverment-entities\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"es\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/mustang-panda-group-that-attacks-goverment-entities\\\/#primaryimage\",\"url\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wp-content\\\/uploads\\\/2021\\\/09\\\/New-scaled.jpg\",\"contentUrl\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wp-content\\\/uploads\\\/2021\\\/09\\\/New-scaled.jpg\",\"width\":2560,\"height\":1133},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/mustang-panda-group-that-attacks-goverment-entities\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Mustang Panda group that attacks goverment entities\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/\",\"name\":\"Truxgo Server Blog\",\"description\":\"Cloud Server and Hosting Tutorials.\",\"publisher\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"es\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#organization\",\"name\":\"Truxgo Server Blog\",\"url\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"es\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wp-content\\\/uploads\\\/2020\\\/08\\\/cropped-truxgo-logo-blanco.png\",\"contentUrl\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wp-content\\\/uploads\\\/2020\\\/08\\\/cropped-truxgo-logo-blanco.png\",\"width\":1250,\"height\":278,\"caption\":\"Truxgo Server Blog\"},\"image\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\"}},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#\\\/schema\\\/person\\\/8b409c26449db6aa09724b45331e333e\",\"name\":\"Truxgo\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"es\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/52691a61c58e68677ed4860007c1bb03b14eabe7350747ab3fad3e17825b4b96?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/52691a61c58e68677ed4860007c1bb03b14eabe7350747ab3fad3e17825b4b96?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/52691a61c58e68677ed4860007c1bb03b14eabe7350747ab3fad3e17825b4b96?s=96&d=mm&r=g\",\"caption\":\"Truxgo\"},\"sameAs\":[\"https:\\\/\\\/truxgoservers.com\\\/blog\"],\"url\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/author\\\/truxgo\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Mustang Panda group that attacks goverment entities - Truxgo Server Blog","description":"There are many groups of cybercriminals that are active, but today we will see a group known's as Mustang Panda.........","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/truxgoservers.com\/blog\/mustang-panda-group-that-attacks-goverment-entities\/","og_locale":"es_MX","og_type":"article","og_title":"Mustang Panda group that attacks goverment entities - Truxgo Server Blog","og_description":"There are many groups of cybercriminals that are active, but today we will see a group known's as Mustang Panda.........","og_url":"https:\/\/truxgoservers.com\/blog\/mustang-panda-group-that-attacks-goverment-entities\/","og_site_name":"Truxgo Server Blog","article_published_time":"2021-09-24T20:59:46+00:00","article_modified_time":"2021-09-24T20:59:47+00:00","og_image":[{"width":2560,"height":1133,"url":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2021\/09\/New-scaled.jpg","type":"image\/jpeg"}],"author":"Truxgo","twitter_card":"summary_large_image","twitter_misc":{"Escrito por":"Truxgo","Tiempo de lectura":"2 minutos"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/truxgoservers.com\/blog\/mustang-panda-group-that-attacks-goverment-entities\/#article","isPartOf":{"@id":"https:\/\/truxgoservers.com\/blog\/mustang-panda-group-that-attacks-goverment-entities\/"},"author":{"name":"Truxgo","@id":"https:\/\/truxgoservers.com\/blog\/#\/schema\/person\/8b409c26449db6aa09724b45331e333e"},"headline":"Mustang Panda group that attacks goverment entities","datePublished":"2021-09-24T20:59:46+00:00","dateModified":"2021-09-24T20:59:47+00:00","mainEntityOfPage":{"@id":"https:\/\/truxgoservers.com\/blog\/mustang-panda-group-that-attacks-goverment-entities\/"},"wordCount":338,"commentCount":0,"publisher":{"@id":"https:\/\/truxgoservers.com\/blog\/#organization"},"image":{"@id":"https:\/\/truxgoservers.com\/blog\/mustang-panda-group-that-attacks-goverment-entities\/#primaryimage"},"thumbnailUrl":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2021\/09\/New-scaled.jpg","keywords":["Cybersecurity"],"articleSection":["Cybersecurity"],"inLanguage":"es","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/truxgoservers.com\/blog\/mustang-panda-group-that-attacks-goverment-entities\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/truxgoservers.com\/blog\/mustang-panda-group-that-attacks-goverment-entities\/","url":"https:\/\/truxgoservers.com\/blog\/mustang-panda-group-that-attacks-goverment-entities\/","name":"Mustang Panda group that attacks goverment entities - Truxgo Server Blog","isPartOf":{"@id":"https:\/\/truxgoservers.com\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/truxgoservers.com\/blog\/mustang-panda-group-that-attacks-goverment-entities\/#primaryimage"},"image":{"@id":"https:\/\/truxgoservers.com\/blog\/mustang-panda-group-that-attacks-goverment-entities\/#primaryimage"},"thumbnailUrl":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2021\/09\/New-scaled.jpg","datePublished":"2021-09-24T20:59:46+00:00","dateModified":"2021-09-24T20:59:47+00:00","description":"There are many groups of cybercriminals that are active, but today we will see a group known's as Mustang Panda.........","breadcrumb":{"@id":"https:\/\/truxgoservers.com\/blog\/mustang-panda-group-that-attacks-goverment-entities\/#breadcrumb"},"inLanguage":"es","potentialAction":[{"@type":"ReadAction","target":["https:\/\/truxgoservers.com\/blog\/mustang-panda-group-that-attacks-goverment-entities\/"]}]},{"@type":"ImageObject","inLanguage":"es","@id":"https:\/\/truxgoservers.com\/blog\/mustang-panda-group-that-attacks-goverment-entities\/#primaryimage","url":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2021\/09\/New-scaled.jpg","contentUrl":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2021\/09\/New-scaled.jpg","width":2560,"height":1133},{"@type":"BreadcrumbList","@id":"https:\/\/truxgoservers.com\/blog\/mustang-panda-group-that-attacks-goverment-entities\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/truxgoservers.com\/blog\/"},{"@type":"ListItem","position":2,"name":"Mustang Panda group that attacks goverment entities"}]},{"@type":"WebSite","@id":"https:\/\/truxgoservers.com\/blog\/#website","url":"https:\/\/truxgoservers.com\/blog\/","name":"Truxgo Server Blog","description":"Cloud Server and Hosting Tutorials.","publisher":{"@id":"https:\/\/truxgoservers.com\/blog\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/truxgoservers.com\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"es"},{"@type":"Organization","@id":"https:\/\/truxgoservers.com\/blog\/#organization","name":"Truxgo Server Blog","url":"https:\/\/truxgoservers.com\/blog\/","logo":{"@type":"ImageObject","inLanguage":"es","@id":"https:\/\/truxgoservers.com\/blog\/#\/schema\/logo\/image\/","url":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2020\/08\/cropped-truxgo-logo-blanco.png","contentUrl":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2020\/08\/cropped-truxgo-logo-blanco.png","width":1250,"height":278,"caption":"Truxgo Server Blog"},"image":{"@id":"https:\/\/truxgoservers.com\/blog\/#\/schema\/logo\/image\/"}},{"@type":"Person","@id":"https:\/\/truxgoservers.com\/blog\/#\/schema\/person\/8b409c26449db6aa09724b45331e333e","name":"Truxgo","image":{"@type":"ImageObject","inLanguage":"es","@id":"https:\/\/secure.gravatar.com\/avatar\/52691a61c58e68677ed4860007c1bb03b14eabe7350747ab3fad3e17825b4b96?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/52691a61c58e68677ed4860007c1bb03b14eabe7350747ab3fad3e17825b4b96?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/52691a61c58e68677ed4860007c1bb03b14eabe7350747ab3fad3e17825b4b96?s=96&d=mm&r=g","caption":"Truxgo"},"sameAs":["https:\/\/truxgoservers.com\/blog"],"url":"https:\/\/truxgoservers.com\/blog\/author\/truxgo\/"}]}},"_links":{"self":[{"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/posts\/3764","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/comments?post=3764"}],"version-history":[{"count":3,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/posts\/3764\/revisions"}],"predecessor-version":[{"id":3782,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/posts\/3764\/revisions\/3782"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/media\/3765"}],"wp:attachment":[{"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/media?parent=3764"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/categories?post=3764"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/tags?post=3764"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}