STATICPLUGIN — Malware Profile
STATICPLUGIN is a downloader known to be leveraged by Mustang Panda and was first observed utilized in 2025. STATICPLUGIN has utilized a valid certificate in order to bypass endpoint security protections. STATICPLUGIN masqueraded as legitimate software installer by using a custom TForm. STATICPLUGIN has been leveraged to deploy a loader that facilitates follow on malware.
MITRE ATT&CK techniques (5)
- T1036.005 Match Legitimate Resource Name or Location
- T1036.008 Masquerade File Type
- T1204.002 Malicious File
- T1553.002 Code Signing
- T1559.001 Component Object Model