TGViewer
Tech Byte™ Tech Byte™ @techbyte · 4K subscribers
Post #1573 363
🚨 Chinese Hackers Exploit MAVInject.exe to Evade Detection! 🚨

The Mustang Panda APT group (aka Earth Preta) is using a stealthy attack technique to bypass security defenses, specifically targeting ESET antivirus users!

🕵️‍♂️ How the Attack Works:
🔹 Spear-phishing emails lure victims with a decoy PDF 📄
🔹 The malware dropper IRSetup.exe executes a legitimate EA application to sideload the TONESHELL backdoor
🔹 MAVInject.exe is used to inject the payload into waitfor.exe, evading ESET detection 🛑
🔹 C2 server connection: Malware establishes a reverse shell via www.militarytc[.]com:443 🌍

🔍 ESET Responds:
ESET denies that this technique bypasses its antivirus, stating they’ve protected against it for years and detected this malware since January. They attribute the attack to CeranaKeeper APT rather than Mustang Panda.

⚠️ Stay Safe!
✅ Be cautious of suspicious emails & attachments 📧
✅ Keep antivirus & security tools updated 🔄
✅ Monitor unexpected process executions 🔍
More from @techbyte
  1. Oct 2, 2026photo post
  2. Oct 1, 202648 tasks, 4 models, one pattern: everyone's better at looking right than moving right. Vis…
  3. Sep 30, 2026photo post
  4. Sep 5, 2026photo post
  5. Jun 22, 2026photo post
  6. Jun 18, 2026Elon Musk, the richest man in the world, has a net worth of approximately $1.4 trillion, T…
Threads Profile ViewerView any public Threads profile without an account.Open ThreadLook →Writing with AI? Make it sound human.Metric37 rewrites AI drafts so they read naturally. Free AI detector, 1,500 words free.Try Metric37 →