🚨 Chinese Hackers Exploit MAVInject.exe to Evade Detection! 🚨
The Mustang Panda APT group (aka Earth Preta) is using a stealthy attack technique to bypass security defenses, specifically targeting ESET antivirus users!
🕵️♂️ How the Attack Works:
🔹 Spear-phishing emails lure victims with a decoy PDF 📄
🔹 The malware dropper IRSetup.exe executes a legitimate EA application to sideload the TONESHELL backdoor
🔹 MAVInject.exe is used to inject the payload into waitfor.exe, evading ESET detection 🛑
🔹 C2 server connection: Malware establishes a reverse shell via www.militarytc[.]com:443 🌍
🔍 ESET Responds:
ESET denies that this technique bypasses its antivirus, stating they’ve protected against it for years and detected this malware since January. They attribute the attack to CeranaKeeper APT rather than Mustang Panda.
⚠️ Stay Safe!
✅ Be cautious of suspicious emails & attachments 📧
✅ Keep antivirus & security tools updated 🔄
✅ Monitor unexpected process executions 🔍
Post #1573
363
