NEW: Group Profiler — instant APT intel lookup. Try it →

Mustang Panda

G0129 China Espionage MITRE ATT&CK →

Also known as: TA416 · RedDelta · BRONZE PRESIDENT · STATELY TAURUS · FIREANT · CAMARO DRAGON · EARTH PRETA · HIVE0154 · TWILL TYPHOON · TANTALUM · LUMINOUS MOTH · UNC6384 · TEMP.Hex · Red Lich · ClumsyToad

Overview

Mustang Panda is a China-based cyber espionage threat actor that has been conducting operations since at least 2012. Mustang Panda has been known to use tailored phishing lures and decoy documents to deliver malicious payloads. Mustang Panda has targeted government, diplomatic, and non-governmental organizations, including think tanks, religious institutions, and research entities, across the United States, Europe, and Asia, with notable activity in Russia, Mongolia, Myanmar, Pakistan, and Vietnam.

Naming & attribution

Mustang Panda is tracked under 16 names across the industry. It uses 85 documented ATT&CK techniques — more than 98% of the 174 groups tracked here. Activity attributed since at least 2012.

Who calls this group what — MITRE lists each alias with the report that used it, but not which vendor coined it.
NameFirst reported by
TA416Proofpoint Threat Research Team
RedDeltaInsikt Group
BRONZE PRESIDENTCounter Threat Unit Research Team
STATELY TAURUSRobert Falcone
FIREANTBroadcom Protection Bulletins
CAMARO DRAGONCohen, Itay. Madej, Radoslaw. Threat Intelligence Team
EARTH PRETANick Dai, Vickie Su, Sunny Lu
HIVE0154Golo Muhr, Joshua Chung
TWILL TYPHOONMicrosoft
TANTALUMMicrosoft
LUMINOUS MOTHMicrosoft
UNC6384Patrick Whitsell
TEMP.HexPatrick Whitsell
Red LichPWC UK
ClumsyToadCloudflare
MUSTANG PANDAMeyers, A

Distinctive techniques

Techniques this group uses that are rare across the other 173 tracked groups — these carry more signal than the near-universal ones.

  • T1129 Shared Modules — used by 1 of 174 groups
  • T1176.002 IDE Extensions — used by 1 of 174 groups
  • T1219.001 IDE Tunneling — used by 1 of 174 groups
  • T1574.005 Executable Installer File Permissions Weakness — used by 1 of 174 groups
  • T1608 Stage Capabilities — used by 1 of 174 groups
  • T1622 Debugger Evasion — used by 1 of 174 groups
  • T1036.007 Double File Extension — used by 2 of 174 groups
  • T1052.001 Exfiltration over USB — used by 2 of 174 groups

Closest groups by technique overlap

Computed from shared ATT&CK techniques. Overlap is not attribution — distinct actors converge on the same tradecraft — but a high share is a useful pivot.

  • APT32 Vietnam — 40 shared techniques (33% overlap)
  • Lazarus Group North Korea — 41 shared techniques (30% overlap)
  • MuddyWater Iran — 35 shared techniques (30% overlap)
  • Kimsuky North Korea — 48 shared techniques (29% overlap)
  • OilRig Iran — 35 shared techniques (28% overlap)
  • FIN7 — 31 shared techniques (26% overlap)

Malware families with current indicators

One family attributed to Mustang Panda, carrying 5 indicators currently tracked from abuse.ch ThreatFox, MalwareBazaar, URLhaus and SSLBL. MITRE documents what a group does; this is what its tooling is doing now.

  • PUBLOAD 5 indicators

Browse or copy the indicators by hash, domain, IP or URL, filtered by age from 1 day to 3 years.

Targets

Civil society

Regions

Germany · United States

Capabilities

  • Exploitation of public-facing / client applications — ATT&CK T1203
  • Custom malware/implant development — ATT&CK: 18 attributed custom malware families

TTPs — 85 techniques across 14 tactics

Reconnaissance

Resource Development

Initial Access

Persistence

Defense Impairment

Credential Access

Lateral Movement

Tools & malware (23)

CANONSTAGER · STATICPLUGIN · ShadowPad · TONESHELL · Cobalt Strike · HIUPAN · Impacket · SplatCloak · PAKLOG · Wevtutil · AdFind · CLAIMLOADER · Mimikatz · PUBLOAD · StarProxy · CorKLOG · RCSession · NBTscan · PoisonIvy · SplatDropper · BOOKWORM · China Chopper · PlugX

Reporting (3)