Mustang Panda Deploys Signed Windows Rootkit to Evade Detection

The cyber-espionage group known as Mustang Panda, also referred to as HoneyMyte, has been observed employing a sophisticated technique to enhance the stealth of its operations. The group has integrated a signed Windows kernel-mode rootkit into its CoolClient backdoor, enabling it to conceal malicious activities effectively.

Recent analyses have identified victims in countries including Myanmar, Mongolia, Pakistan, and Russia, with confirmed government entities among the targets. The deployment of CoolClient typically follows an initial infection with the PlugX malware, suggesting a multi-stage attack strategy.

Technical Details of the Rootkit Deployment

The rootkit is introduced when CoolClient gains full access to the Service Control Manager (SCM) and possesses the SeTcbPrivilege privilege. If these conditions are unmet, the malware bypasses driver deployment, proceeding directly to the final-stage implant. This approach indicates a conditional deployment strategy aimed at maximizing stealth.

Once installed, the kernel-mode driver operates as a Windows service, receiving commands from the user-mode backdoor via input/output control (IOCTL) requests. This setup allows the rootkit to perform various functions, including keylogging, clipboard data theft, credential harvesting, file management, and system reconnaissance. Additionally, it supports the execution of further functionalities through plugins.

Initial Infection and Persistence Mechanisms

In a documented campaign targeting Myanmar, Mustang Panda utilized PlugX as the initial post-compromise implant to deploy CoolClient. The attackers added exclusions to Microsoft Defender for a counterfeit Windows Defender installation directory and a renamed sideloading executable. They then copied the malware components into this directory, renaming a legitimate Sangfor executable to ‘defender.exe’ to facilitate DLL sideloading. Persistence was established through a scheduled task that launched the binary with SYSTEM privileges upon system startup.

The execution chain begins when the legitimate Sangfor application loads a malicious ‘libngs.dll’, which decrypts and executes the second-stage component ‘loadcert.ini’. This component handles various tasks, including persistence, registry modifications, User Account Control (UAC) bypass, process injection, driver deployment, and loading the final-stage ‘cert.ini’ implant responsible for command-and-control communications and backdoor functionality.

Signed Driver Enhances Stealth Capabilities

When the necessary privileges are available, ‘loadcert.ini’ extracts an embedded LZMA-compressed kernel driver, writes it to disk as ‘msagent.sys’, and creates and starts a driver service named ‘msagent’. Notably, the driver is digitally signed with a certificate issued to Nanjing Ranyi Technology Co., Ltd., valid from August 2013 to September 2014. This use of a signed driver underscores the attackers’ efforts to evade detection by security software that typically trusts signed drivers.

Once loaded, the driver receives configuration from the CoolClient user-mode component through IOCTL requests. This communication allows the rootkit to execute its functions while remaining concealed from user-mode security tools.

The integration of a signed kernel-mode rootkit into the CoolClient backdoor represents a significant advancement in Mustang Panda’s evasion techniques. By operating at the kernel level, the rootkit can effectively hide malicious processes and files, intercept and filter I/O operations before they reach antivirus software, and disable security tools like Microsoft Defender. This development highlights the increasing sophistication of state-sponsored threat actors and underscores the need for robust security measures capable of detecting and mitigating such advanced threats.