Find notable cyber news and cases, enriched with sources, timelines, and signals.

Bookworm malware used by Mustang Panda since 2015

Malware Activity
First reported
Last updated
Happening score
H score 23
1 unique sources, 1 articles

Summary

Hide ▲

The long-running Bookworm malware used by Mustang Panda remains a serious threat because it can maintain control over compromised systems. It supports arbitrary commands, file transfer, data exfiltration, and persistent access. A separate March wave targeted ASEAN countries, showing continued operational use of the tool.

Related Happenings

Showboat Linux post-exploitation backdoor framework

Malware Activity
H score16 First: 21.05.2026 17:17 Last: 21.05.2026 17:17 Sources 1

About this happening: The Showboat Linux malware has been identified as a modular post-exploitation framework used since at least mid-2022, raising the risk of persistent access on compromi...

Webworm EchoCreep and GraphWorm backdoor expansion

Malware Activity
H score28 First: 20.05.2026 15:51 Last: 20.05.2026 15:51 Sources 1

About this happening: Webworm expanded its malware arsenal in 2025 with the custom backdoors EchoCreep and GraphWorm, increasing its ability to run stealthy command-and-control oper...

ABCDoor backdoor activity in Silver Fox attacks

Malware Activity
H score23 First: 04.05.2026 14:35 Last: 04.05.2026 14:35 Sources 1

About this happening: The newly identified ABCDoor backdoor is being used in real-world attacks by Silver Fox, expanding the group's malware set and increasing the risk of covert remote acc...

Mustang Panda, CL-STA-1048, and CL-STA-1049 Southeast Asia government campaign

Campaign
H score32 First: 30.03.2026 10:00 Last: 30.03.2026 10:00 Sources 1

About this happening: Three China-aligned clusters targeted a government organization in Southeast Asia, signaling a coordinated campaign built for long-term access. The activity spans Mu...

UAT-9244 TernDoor, PeerTime, and BruteEntry malware activity

Malware Activity
H score22 First: 06.03.2026 01:19 Last: 06.03.2026 01:19 Sources 1

About this happening: A China-linked malware cluster has been using TernDoor, PeerTime, and BruteEntry to compromise telecommunication providers in South America and turn infected s...

Timeline

  1. 27.09.2025 15:06 2 articles · 9mo ago

    Mustang Panda's Bookworm use since 2015 and March ASEAN targeting

    Technical Analysis Update

    Bookworm malware used by Mustang Panda since 2015 supports arbitrary command execution, file upload and download, data exfiltration, and persistent access, while a separate March campaign used DLL side-loading and legitimate-looking domains or compromised infrastructure to distribute the malware to ASEAN-affiliated countries.

    Show sources