Malicious emails purporting to be U.S. diplomatic briefings have been used by Chinese state-sponsored threat operation Mustang Panda, also known as HoneyMyte, to target government officials and diplomats around the world with surveillance tools as part of a cyberespionage campaign between late December 2025 and mid-January 2026, reports The Hacker News.Included in Mustang Panda's phishing emails were policy update- or internal briefing-related subject lines and a malicious PDF document that triggered the deployment of a custom PlugX surveillance tool variant dubbed "DOPLUGS" for covert data gathering activities, according to Dream Research Labs. Additional malicious tools are being retrieved by DOPLUGS via PowerShell."The combination of delivery techniques, loader architecture, malware characteristics, lure theming, and overlapping infrastructure observed in this campaign aligns with publicly documented activity attributed to Mustang Panda," said researchers, who believe that similar intrusions may only become more prevalent amid mounting geopolitical tensions around the world.
Threat Intelligence, Government security
Global Mustang Panda surveillance campaign targets government officials, diplomats

(Adobe Stock)
Related Events
Get daily email updates
SC Media's daily must-read of the most current and pressing daily news
You can skip this ad in 5 seconds



