ThreatCluster

Mustang Panda Launches PlugX RAT Campaign via Fake Browser Update

2 Jun 2026 GbhackersCybersecuritynews 83% similarity 76
Share:

Article Content

Browse articles
ThreatCluster

Mustang Panda, a Chinese state-sponsored threat group, has initiated a cyberattack campaign deploying the PlugX remote access tool (RAT). The attack utilizes a fake browser updater to trick users into downloading a multi-stage malware loader. This loader employs a combination of LNK and PowerShell scripts to sideload PlugX through a legitimate antivirus binary. The malware communicates with a hard-coded command and control (C2) server over HTTPS, using layered encryption to conceal its configuration. The campaign is characterized by its sophisticated methods and is indicative of the group's ongoing focus on espionage and data theft. Organizations using G DATA antivirus software may be particularly vulnerable to this attack. The current status of the campaign is active, with ongoing monitoring required.

Key Points: • Mustang Panda is deploying PlugX RAT through a fake browser updater. • The attack uses a multi-stage LNK and PowerShell loader to sideload malware. • G DATA antivirus users are specifically targeted in this campaign.

ThreatCluster AI

Timeline

2026-06-02
Mustang Panda cyberattack campaign reported
Mustang Panda is using a fake browser updater to deploy PlugX RAT via a multi-stage loader, affecting users of G DATA antivirus.
Cybersecuritynews
2026-06-02
Attack method detailed
The campaign utilizes LNK and PowerShell scripts to sideload PlugX, hiding its communication behind encryption.
Gbhackers

Community

Browse all →