CANONSTAGER
S1237 · Windows
CANONSTAGER is a loader known to be leveraged by Mustang Panda and was first observed utilized in 2025. Mustang Panda utilizes DLL side-loading to execute within the victim environment prior to delivering a follow-on malicious encrypted payload. CANONSTAGER leverages Thread Local Storage (TLS) and Native Windows APIs within the victim environment to elude detections.
CANONSTAGER also hides its code utilizing window procedures and message queues.
ATT&CK S1237
Sigma rules0
YARA rules0
Live IOCs0