CANONSTAGER

MITRE ATT&CK: S1237 View on attack.mitre.org

Aliases: CANONSTAGER

First seen
2025-01-01 00:00:00
Malware type
loader
Family
Malware family
Operating systems
windows
Profile updated
2026-07-07 13:16:55

Targeted industries: government-and-public-sector technology-and-telecommunications

Context

CANONSTAGER is a loader known to be leveraged by Mustang Panda and was first observed utilized in 2025. Mustang Panda utilizes DLL side-loading to execute within the victim environment prior to delivering a follow-on malicious encrypted payload. CANONSTAGER leverages Thread Local Storage (TLS) and Native Windows APIs within the victim environment to elude detections. CANONSTAGER also hides its code utilizing window procedures and message queues.

Detection coverage

  • 113 Sigma rules

Malware & tools used

  • Dynamic API Resolution (attack-pattern)
  • Thread Local Storage (attack-pattern)
  • Match Legitimate Resource Name or Location (attack-pattern)
  • DLL (attack-pattern)
  • Native API (attack-pattern)
  • Hidden Window (attack-pattern)

Used by threat actors

Reports & references

  • cloud.google.com — Prc Nexus Espionage Targets Diplomats (report)
  • MITRE ATT&CK — S1237 (report)

External references