Chinese hackers turn to new malware for government attacks

Chinese state-sponsored cybercriminal Mustang Panda (also known as LuminousMoth, Camaro Dragon, HoneyMyte and more) is launching malware campaigns targeting high-value targets, including government agencies in Asia.

The group used a variant of the HIUPAN worm to deliver PUBLOAD malware into its targets’ networks via removable drives. The HIUPAN worm moved all of its files to a hidden directory to hide its presence, leaving only one seemingly legitimate file visible (“USBConfig.exe”) to trick the user.