Chinese APTs Target Orgs with Korplug and Malicious USBs

Chinese APTs Target Orgs with Korplug and Malicious USBs

Mustang Panda Escalates Cyber Espionage in Europe with Hybrid USB and Malware Toolset

A China-linked cyber threat actor, dubbed Mustang Panda, has launched a new wave of cyber espionage campaigns across Europe, raising alarms within national security and critical infrastructure circles. This operation marks a strategic shift, as the group intensifies its focus on government agencies and maritime logistics firms, exploiting gaps in endpoint and physical security.

At the center of these campaigns is a dual-pronged approach: the use of malicious USB drives to breach hardened environments, and the deployment of Korplug loaders rewritten in diverse programming languages—an innovation designed to bypass modern detection technologies.

Weaponizing the Human Element

Instead of relying solely on network-based intrusions, Mustang Panda is targeting the weakest link: people. By distributing infected USB drives, often disguised as legitimate devices or dropped in proximity to high-value targets, the attackers bypass perimeter defenses entirely. This method is particularly effective against air-gapped systems, where traditional attack vectors fall short.

Once connected, these USB drives silently launch payloads that initiate a stealthy infection chain. The malware, often using techniques consistent with MITRE ATT&CK’s T1091, plants loaders that fetch a full-featured backdoor—Korplug, Mustang Panda’s hallmark remote access tool.

Korplug Redefined

What sets this campaign apart is the technical reinvention of Korplug. Traditionally a C++-based backdoor, the malware now appears in multiple flavors—Go, Nim, and Delphi—each tailored to evade different types of security tools. This diversity complicates detection and forces defenders to rethink how they model threats.

  • Nim-based variants, for example, exploit the rarity of Nim malware in enterprise environments, dodging heuristic and signature-based detection engines.
  • Go implementations are compact, multi-platform, and easily obfuscated, offering resilience against reverse engineering.
  • Delphi variants leverage older system APIs, likely to increase compatibility with legacy endpoints often found in maritime tech stacks.

This evolution suggests an adaptive adversary that is deeply familiar with European enterprise environments and their blind spots.

Strategic Implications

Recent intelligence confirms that Mustang Panda has been the most active China-aligned APT operating in Europe over the past six months, with campaigns spanning the UK, Netherlands, Norway, Denmark, Bulgaria, Poland, Greece, and Hungary. These aren’t one-off incidents—they represent a coordinated and sustained offensive.

The deployment of MSC-based downloaders in tandem with Korplug loaders also signals a broader capability to pivot post-compromise, enabling the retrieval of second-stage tools depending on the target’s environment and mission objectives.

Defensive Measures

For security teams, this campaign underscores the need to go beyond traditional defenses:

  • Restrict and monitor USB device usage at a policy and hardware level.
  • Deploy EDR solutions capable of behavioral analysis and memory inspection.
  • Regularly update threat models to account for loader variations written in non-traditional languages.
  • Prioritize staff awareness training on physical infiltration methods like malicious media drops.

Organizations in critical sectors—especially those involved in government and maritime operations—must treat physical media as a potential intrusion vector, not just an outdated attack method.

More Articles & Posts