SolidPDFCreator: Mustang Panda Stage-1 Backdoor Targeting India via DLL Side-Loading — Threadlinqs Intelligence
As of 2026-07-14, SolidPDFCreator: Mustang Panda Stage-1 Backdoor Targeting India via DLL Side-Loading is a high-severity malware threat attributed to Mustang Panda (China), tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 26 indicators of compromise.
Threat ID: TL-2026-1292 · Severity: HIGH · Status: ACTIVE · Category: MALWARE
Attribution: Mustang Panda · China · ESPIONAGE
Mustang Panda (China-nexus APT) is spear-phishing Indian targets with ZIP attachments that DLL side-load a malicious SolidPDFCreator.dll stage-1 backdoor into C:\ProgramData\IDM\logs\, gaining
In July 2026, researchers at the kienmanowar Blog documented a new Mustang Panda stage-1 backdoor tracked as "SolidPDFCreator," part of a campaign labeled "Target India – Campaign 3." The infection begins with a spear-phishing email carrying a ZIP attachment named "Letter to His Excellency the President.zip" that uses double-extension/hidden-extension obfuscation to trick the victim into executing a legitimate-looking installer (MediumInstStart.exe) alongside a malicious DLL (SolidPDFCreator.dll). Because the legitimate loader binary searches its own directory before trusted system paths, the malicious DLL is loaded instead of (or ahead of) the genuine library — a classic DLL search-order hijack / side-loading technique long associated with Mustang Panda's PlugX, TONESHELL and related toolsets.
Once loaded, SolidPDFCreator drops itself and its loader copy into C:\ProgramData\IDM\logs\, installs a scheduled task named MediumNetMonIt (trigger ID DailyTriggerId) to run with SYSTEM-level privilege on a daily basis, and creates a named event/mutex (uydgcfteionxcfd) to prevent multiple concurrent instances. The DLL's real entry point is exposed through the C++-mangled export GetSPApp (?GetSPApp@@YAAAVCSPApp@@XZ), which dispatches to internal installer/loader logic (Install_CopyMalwareToIDMLogs, IsInstalledInIDMLogs).
The payload itself is protected by a 34-byte cyclic XOR key (yrty!@#123$09*gdt%dgt$874Tydghsbyr) applied across 186 individually-scrambled 187-byte chunks, yielding a 34,816-byte shellcode blob. At execution time the malware allocates RWX memory via VirtualAlloc + VirtualProtect(PAGE_EXECUTE_READWRITE) and abuses the EnumSystemLocalesA() Windows API as a callback-execution primitive to redirect control flow into the decrypted shellcode at offset base+0xD0 — a technique intended to defeat behavioral sandboxes that hook more conventional execution APIs. The shellcode resolves further Windows APIs via PEB-walk export hashing rather than static imports, further complicating static and dynamic analysis.
Mustang Panda (tracked under many vendor names — TA416, RedDelta, BRONZE PRESIDENT, STATELY TAURUS, FIREANT, CAMARO DRAGON, EARTH PRETA, HIVE0154, TWILL TYPHOON, TANTALUM, LUMINOUS MOTH, UNC6384, TEMP.Hex, Red Lich, ClumsyToad; MITRE ATT&CK G0129) is a China-nexus espionage actor active since at least 2012, whose long-running mission is collection of diplomatic, political, military and economic intelligence for the Chinese state. The group has repeatedly targeted Indian government, defense, and now energy-sector entities throughout 2026: a June 2026 campaign delivered SHARDLOADER, MINIRECON and ZOHOMURK (the latter abusing Zoho WorkDrive as a C2 channel) against Indian government and energy-sector victims interested in India-Taiwan defense ties and hydropower plans, while a separate April 2026 wave used a LOTUSLITE variant against Indian banks and South Korean policy circles. SolidPDFCreator represents a further diversification of Mustang Panda's stage-1 loader toolkit against the same strategic target set, continuing the group's historical pattern of rapid tooling iteration (PlugX, PUBLOAD, TONESHELL, BOOKWORM, Cobalt Strike, SHARDLOADER, ZOHOMURK, MINIRECON, LOTUSLITE) paired with consistent DLL side-loading tradecraft and scheduled-task persistence.
Weaknesses (CWE)
CWE-506, CWE-427, CWE-694
Target sectors: government administration, defense, energy, banking, diplomatic
Target regions: india, South Asia
Detections & IOCs
As of 2026-07-28, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 26 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
Community OSINT corroboration
1 of this threat's indicators have also been reported by the open-source security community, which observed at least one of them before this report was published. Community sightings are unverified and are kept separate from Threadlinqs' curated indicators. Indicator values, reporters and campaign linkage are available to authenticated Red-tier users.
MALWARE, HIGH, threat intelligence, cybersecurity, T1566, T1204, T1106, T1059, T1053, T1574, T1053, T1574, T1027, T1027