CANONSTAGER
MITRE ATT&CK: S1237 View on attack.mitre.org
Aliases: CANONSTAGER
- First seen
- 2025-01-01 00:00:00
- Malware type
- loader
- Family
- Malware family
- Operating systems
- windows
- Profile updated
- 2026-07-07 13:16:55
Targeted industries: government-and-public-sector technology-and-telecommunications
Context
CANONSTAGER is a loader known to be leveraged by Mustang Panda and was first observed utilized in 2025. Mustang Panda utilizes DLL side-loading to execute within the victim environment prior to delivering a follow-on malicious encrypted payload. CANONSTAGER leverages Thread Local Storage (TLS) and Native Windows APIs within the victim environment to elude detections. CANONSTAGER also hides its code utilizing window procedures and message queues.
Detection coverage
- 113 Sigma rules
Malware & tools used
- Dynamic API Resolution (attack-pattern)
- Thread Local Storage (attack-pattern)
- Match Legitimate Resource Name or Location (attack-pattern)
- DLL (attack-pattern)
- Native API (attack-pattern)
- Hidden Window (attack-pattern)
Used by threat actors
- Mustang Panda (threat-actor)
Reports & references
- cloud.google.com — Prc Nexus Espionage Targets Diplomats (report)
- MITRE ATT&CK — S1237 (report)