Executive Summary
In early 2026, the Mustang Panda APT group deployed a sophisticated multi-layer execution chain using a PlugX variant. The campaign begins with a social engineering lure involving a fake 'Browser Update' UI that downloads a signed MSI installer. This installer drops a three-file set designed to exploit DLL sideloading through a legitimate, signed G DATA AntiVirus binary (Avk.exe).
Technically, the malware exhibits high levels of evasion, including custom API hashing (DJB2 and ROL19), control-flow flattening, and the use of the RtlRegisterWait callback to hide execution from EDR monitors. The final payload is manually mapped into memory, bypassing standard OS loaders, and establishes persistence via registry Run keys with randomized 'filler' arguments to control execution logic.
This activity demonstrates the group's continued reliance on sideloading and their evolution in using legitimate software namespaces (like G DATA) to mask malicious presence. Organizations should prioritize monitoring for unusual behavior associated with signed third-party binaries and unauthorized changes to the %PUBLIC% directory.
