Mustang Panda — APT Profile
Mustang Panda is a China-based cyber espionage threat actor that has been conducting operations since at least 2012. Mustang Panda has been known to use tailored phishing lures and decoy documents to deliver malicious payloads. Mustang Panda has targeted government, diplomatic, and non-governmental organizations, including think tanks, religious institutions, and research entities, across the United States, Europe, and Asia, with notable activity in Russia, Mongolia, Myanmar, Pakistan, and Vietnam.Also tracked as
TA416, RedDelta, BRONZE PRESIDENT, STATELY TAURUS, FIREANT, CAMARO DRAGON, EARTH PRETA, HIVE0154, TWILL TYPHOON, TANTALUM, LUMINOUS MOTH, UNC6384, TEMP.Hex, Red Lich
Tools & malware
- AdFind Network Reconnaissance
- BOOKWORM Backdoor
- CANONSTAGER Backdoor
- China Chopper Web Shell
- CLAIMLOADER Loader
- Cobalt Strike Adversary Simulation
- CorKLOG Rootkit
- HIUPAN Worm
- Impacket Network Toolkit
- Mimikatz Credential Harvesting
- NBTscan Network Reconnaissance
- PAKLOG Backdoor
- PlugX Backdoor
- PoisonIvy Remote Access Trojan
- PUBLOAD Loader
- RCSession Backdoor
- ShadowPad Backdoor
- SplatCloak Defense Evasion
- SplatDropper Loader
- StarProxy Tunneling Tool
- STATICPLUGIN Backdoor
- TONESHELL Backdoor
- Wevtutil Discovery
Vendor research
- LuminousMoth - PlugX, File Exfiltration and Persistence Revisited Botezatu, B and etl
- LuminousMoth APT: Sweeping attacks for the chosen few Lechtik, M, and etl
- Introducing the 2026 Cloudflare Threat Report Cloudflare
- BRONZE PRESIDENT Targets NGOs Counter Threat Unit Research Team
- Stately Taurus Targets Myanmar Amidst Concerns over Military Junta’s Handling of Rebel Attacks CSIRT CTI
- How Microsoft names threat actors Microsoft
- BRONZE PRESIDENT Targets Russian Speakers with Updated PlugX Secureworks Counter Threat Unit Research Team
- BRONZE PRESIDENT Targets Government Officials Secureworks Counter Threat Unit Research Team
- Mustang Panda APT Group Uses European Commission-Themed Lure to Deliver PlugX Malware EclecticIQ Mustang Panda PlugX
- Hive0154 aka Mustang Panda shifts focus on Tibetan community to deploy Pubload backdoor IBM
- Hive0154 targeting US, Philippines, Pakistan and Taiwan in suspected espionage campaign 2025_IBM_PUBLOAD_TONESHELL_HIUPAN_CLAIMLOADER_MUSTANG PANDA
- CHINESE STATE-SPONSORED GROUP ‘REDDELTA’ TARGETS THE VATICAN AND CATHOLIC ORGANIZATIONS Recorded Future
- Emulating the Politically Motivated Chinese APT Mustang Panda ATTACKIQ
- Earth Preta Evolves its Attacks with New Malware and Strategies Trend Micro
- Cyberespionage Attacks Against Southeast Asian Government Linked to Stately Taurus, Aka Mustang Panda Palo Alto
- Meet CrowdStrike’s Adversary of the Month for June: MUSTANG PANDA Crowdstrike
- Earth Preta Mixes Legitimate and Malicious Components to Sidestep Detection Trend Micro
- Earth Preta Spear-Phishing Governments Worldwide 2022 November_TrendMicro_Earth Preta_Toneshell_Pubload
- Deception in Depth: PRC-Nexus Espionage Campaign Hijacks Web Traffic to Target Diplomats Google
- TA416 Goes to Ground and Returns with a Golang PlugX Malware Loader Proofpoint
- Cyber Threats 2020: A Year in Retrospect PWC
- The Good, the Bad, and the Web Bug: TA416 Increases Operational Tempo Against European Governments as Conflict in Ukraine Escalates Proofpoint
- Bookworm Trojan: A Model of Modular Architecture Unit42
- Stately Taurus Activity in Southeast Asia Links to Bookworm Malware Palo Alto Networks
- BRONZE PRESIDENT Targets Russian Speakers with Updated PlugX Sophos