STATICPLUGIN
S1238 · Windows
STATICPLUGIN is a downloader known to be leveraged by Mustang Panda and was first observed utilized in 2025. STATICPLUGIN has utilized a valid certificate in order to bypass endpoint security protections. STATICPLUGIN masqueraded as legitimate software installer by using a custom TForm.
STATICPLUGIN has been leveraged to deploy a loader that facilitates follow on malware.
ATT&CK S1238
Sigma rules0
YARA rules0
Live IOCs0