Mustang Panda — APT Profile
Mustang Panda is a China-based cyber espionage threat actor that has been conducting operations since at least 2012. Mustang Panda has been known to use tailored phishing lures and decoy documents to deliver malicious payloads. Mustang Panda has targeted government, diplomatic, and non-governmental organizations, including think tanks, religious institutions, and research entities, across the United States, Europe, and Asia, with notable activity in Russia, Mongolia, Myanmar, Pakistan, and Vietnam.Description reproduced from MITRE ATT&CK. © The MITRE Corporation, reproduced and distributed with permission.
Also tracked as
TA416, RedDelta, BRONZE PRESIDENT, STATELY TAURUS, FIREANT, CAMARO DRAGON, EARTH PRETA, HIVE0154, TWILL TYPHOON, TANTALUM, UNC6384, TEMP.Hex, Red Lich, Vertigo Panda
IntelFusions coverage (11)
- Chinese spy backdoor now hides itself inside Windows 2026-08-14 · Nation-State
- State-backed hackers hide attacks inside AI tools and trusted cloud apps 2026-07-14 · Nation-State
- Chinese hackers hit Southeast Asian energy grids with a new backdoor 2026-06-26 · Nation-State
- New SharkLoader malware hits diplomats and governments with Cobalt Strike 2026-06-24 · Nation-State
- China-linked groups drive most state-backed attacks on tech firms 2026-06-10 · Nation-State
- Hive0154 (Mustang Panda) Deploys Toneshell9 with Proxy-Blended C2 and SnakeDisk USB Worm Targeting Thailand Amid Cambodia Border Crisis 2026-02-16 · Nation-State
- Hive0145 Evolves Beyond Credential Theft: StarFish Backdoor and Persistent Access Mark a New Phase for Strela Stealer Operator 2026-02-16 · Cyber Incidents
- Mustang Panda Targets Vietnamese Organizations with forfiles.exe Abuse, DLL Sideloading, and RC4 MAC Address Exfiltration in Dual-Campaign Espionage Operation 2026-02-16 · Nation-State
- Mustang Panda Deploys Nim-Written DLL Loader with Custom RC4 to Target Taiwanese Government and Diplomats Using 2024 Presidential Election Lure 2026-02-16 · Nation-State
- Stately Taurus (Mustang Panda) Conducts Two-Year Southeast Asian Government Espionage Operation: Three-DLL ToneShell Variant, ShadowPad, and Continuous File Exfiltration via Dropbox 2026-02-16 · Nation-State
- Mustang Panda Targets Australian Trade Minister in AUKUS-Motivated Campaign: SolidPDFCreator DLL Sideloading and PlugX Stager with Microsoft Host Header Masquerade 2026-02-16 · Nation-State
Tools & malware
- AdFind Network Reconnaissance
- BOOKWORM Backdoor
- CANONSTAGER Backdoor
- China Chopper Web Shell
- CLAIMLOADER Loader
- Cobalt Strike Adversary Simulation
- CorKLOG Rootkit
- HIUPAN Worm
- Impacket Network Toolkit
- Mimikatz Credential Harvesting
- NBTscan Network Reconnaissance
- PAKLOG Backdoor
- PlugX Backdoor
- PoisonIvy Remote Access Trojan
- PUBLOAD Loader
- RCSession Backdoor
- ShadowPad Backdoor
- SplatCloak Defense Evasion
- SplatDropper Loader
- StarProxy Tunneling Tool
- STATICPLUGIN Backdoor
- TONESHELL Backdoor
- Wevtutil Discovery
Vendor research
- full technical write up Kaspersky
- Introducing the 2026 Cloudflare Threat Report Cloudflare
- BRONZE PRESIDENT Targets NGOs Counter Threat Unit Research Team
- Stately Taurus Targets Myanmar Amidst Concerns over Military Junta’s Handling of Rebel Attacks CSIRT CTI
- BRONZE PRESIDENT Targets Russian Speakers with Updated PlugX Secureworks Counter Threat Unit Research Team
- BRONZE PRESIDENT Targets Government Officials Secureworks Counter Threat Unit Research Team
- How Microsoft names threat actors Microsoft
- Hive0154 aka Mustang Panda shifts focus on Tibetan community to deploy Pubload backdoor IBM
- Hive0154 targeting US, Philippines, Pakistan and Taiwan in suspected espionage campaign 2025_IBM_PUBLOAD_TONESHELL_HIUPAN_CLAIMLOADER_MUSTANG PANDA
- CHINESE STATE-SPONSORED GROUP ‘REDDELTA’ TARGETS THE VATICAN AND CATHOLIC ORGANIZATIONS Recorded Future
- Emulating the Politically Motivated Chinese APT Mustang Panda ATTACKIQ
- Earth Preta Evolves its Attacks with New Malware and Strategies Trend Micro
- Cyberespionage Attacks Against Southeast Asian Government Linked to Stately Taurus, Aka Mustang Panda Palo Alto
- Meet CrowdStrike’s Adversary of the Month for June: MUSTANG PANDA Crowdstrike
- Earth Preta Mixes Legitimate and Malicious Components to Sidestep Detection Trend Micro
- Earth Preta Spear-Phishing Governments Worldwide 2022 November_TrendMicro_Earth Preta_Toneshell_Pubload
- Deception in Depth: PRC-Nexus Espionage Campaign Hijacks Web Traffic to Target Diplomats Google
- TA416 Goes to Ground and Returns with a Golang PlugX Malware Loader Proofpoint
- Mustang Panda’s Hodur: Old tricks, new Korplug variant ESET
- The Good, the Bad, and the Web Bug: TA416 Increases Operational Tempo Against European Governments as Conflict in Ukraine Escalates Proofpoint
- Bookworm Trojan: A Model of Modular Architecture Unit42
- Stately Taurus Activity in Southeast Asia Links to Bookworm Malware Palo Alto Networks
- BRONZE PRESIDENT Targets Russian Speakers with Updated PlugX Sophos
- BRONZE PRESIDENT Targets Government Officials Sophos
- Latest Mustang Panda Arsenal: ToneShell and StarProxy | P1 Zscaler
Countries linked to this actor
- Taiwan targets
- Belgium targets
- Vietnam targets
- Thailand targets
- Indonesia targets
- China origin
- Singapore targets
- India targets
- Myanmar targets
- Serbia targets
- Qatar targets
- Nigeria targets
- Hungary targets
- Philippines targets
- Malaysia targets
- Nepal targets
- Mongolia targets
- Vatican City targets
- Guyana targets
- Ghana targets