Threat Group Cards: A Threat Actor Encyclopedia Archived: 2026-04-05 14:24:00 UTC Home > List all groups > List all tools > List all groups using tool WispRider Tool: WispRider Names WispRider Category Malware Type Backdoor Description (Check Point) WispRider is a side-loaded DLL which contains both the USB infector component and the backdoor itself. It first creates a mutex to ensure there is a single instance running and checks that the executable that side-loaded it was executed with the proper argument. Next, it searches for a configuration file by first identifying a currently running directory from which the executable runs, and then recursively scanning from that directory to check each file as a potential config file candidate. Information Last change to this tool card: 23 June 2023 Download this tool card in JSON format All groups using tool WispRider Changed Name Country Observed APT groups Mustang Panda, Bronze President 2012-Jun 2025 1 group listed (1 APT, 0 other, 0 unknown) Source: https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=5d476448-f2e8-46dd-b45c-c034edb268a8 https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=5d476448-f2e8-46dd-b45c-c034edb268a8 Page 1 of 1