Year2024 |
MonthJuly |
Reference number20240702 |
Impact areaVessel |
Incident locationNorway, Greece, Netherlands |
Incident countryNorway, Greece, Netherlands |
Victim countryNorway, Greece, Netherlands |
Victim identityUnknown |
Victim TypeVessel |
MethodMalware |
Attacker countryChina |
Mustang Panda, a threat actor, targeted cargo shipping companies in Europe in early 2024 using Korplug loaders. These loaders, dropped from USB drives with suspicious filenames, compromised systems in Norway, Greece, and the Netherlands. Some malware samples were blocked, but others had altered signatures and utilized DLL hijacking. The group also shares similarities with a separate actor, CeranaKeeper, which uses different tools like the TONESHELL backdoor. Both may have overlapping resources, but they operate independently.