Chinese hackers hit IBM reality show. 2 fake companies and 0 suspicions from Beijing's best burglars

Depov

Moderator
Staff member
MODERATOR
ULTIMATE
SUPREME
PREMIUM
MEMBER
Joined
Feb 18, 2025
Messages
422
Reaction score
685
Deposit
0$
IBM specialists lured Mustang Panda hackers into fake corporate networks and watched their actions live for several days. The operators did not recognize the trap, deployed the previously unknown backdoor Havencode, sought credentials and in one case even stole specially prepared documents for them.

The IBM X-Force team links activity to the ITG27 group, formerly known as Hive0154. Her operations overlap with campaigns that other companies track under the names Mustang Panda, Stately Taurus, Camaro Dragon, Twill Typhoon and Earth Preta. The group is associated with China, and its main goal is cyber espionage.

To watch hackers, IBM, together with Deception.Pro, created two realistic false organizations. The first depicted a company working with electrical networks, the second - the state department. The attackers kept the presence for several days, studied computers and the network, collected credentials and installed malicious programs. All manual actions of operators occurred on weekdays from 08:00 to 18:00 Chinese standard time.

In the first trap, Mustang Panda installed a previously unknown Havencode. This backdoor supports VNC and allows you to remotely view the desktop of an infected computer and manage applications. In the second environment, the hackers found the substitute documents, packed them in the archive and sent to the SFTP server. Thus, the specialists were able to see not only malicious programs, but also the actions of operators after they entered the network.


The specialists continued to observe the campaign that Acronis had previously discovered. Mustang Panda attacks India's government structures and energy sector using baits on hydropower projects. In May 2026, the attackers sent out a PDF file disguised as a document from the Ministry of Foreign Affairs of Nepal. The link inside led to the archive with a malicious bootloader.

In the IBM chain, the Claimloader bootloader launched Toneshell v10. The new version of Toneshell has switched to WebSocket secure connections via WinHTTP and can now remotely execute commands and transfer files. To gain a foothold in the system, the malware added itself to the Windows autorun section and worked entirely in memory.

IBM believes that interest in India's energy industry fits into how the ITG27 conducts broader intelligence activities. Experts recommend tracking the characteristic sequences of intelligence teams, checking whether the systems are infected, according to published signs and keep event logs for at least 90 days, as Mustang Panda operators can return to the infected system a few days later.
 
Top Bottom