FORENSIA

THREAT_ACTOR · G0129

Mustang Panda

Also known as: Mustang Panda, TA416, RedDelta, BRONZE PRESIDENT, STATELY TAURUS, FIREANT, CAMARO DRAGON, EARTH PRETA, HIVE0154, TWILL TYPHOON, TANTALUM, LUMINOUS MOTH, UNC6384, TEMP.Hex, Red Lich, ClumsyToad

Profile

Mustang Panda is a China-based cyber espionage threat actor that has been conducting operations since at least 2012. Mustang Panda has been known to use tailored phishing lures and decoy documents to deliver malicious payloads. Mustang Panda has targeted government, diplomatic, and non-governmental organizations, including think tanks, religious institutions, and research entities, across the United States, Europe, and Asia, with notable activity in Russia, Mongolia, Myanmar, Pakistan, and Vietnam.

MITRE ATT&CK ↗

Techniques

85 ATT&CK techniques attributed to this actor.

T1001.003 Protocol or Service ImpersonationT1003 OS Credential DumpingT1003.001 LSASS MemoryT1003.003 NTDST1003.006 DCSyncT1016 System Network Configuration DiscoveryT1018 Remote System DiscoveryT1027 Obfuscated Files or InformationT1027.007 Dynamic API ResolutionT1027.012 LNK Icon SmugglingT1027.016 Junk Code InsertionT1036.005 Match Legitimate Resource Name or LocationT1036.007 Double File ExtensionT1036.008 Masquerade File TypeT1041 Exfiltration Over C2 ChannelT1046 Network Service DiscoveryT1047 Windows Management InstrumentationT1048.003 Exfiltration Over Unencrypted Non-C2 ProtocolT1049 System Network Connections DiscoveryT1052.001 Exfiltration over USBT1053.005 Scheduled TaskT1057 Process DiscoveryT1059 Command and Scripting InterpreterT1059.001 PowerShellT1059.003 Windows Command ShellT1059.005 Visual BasicT1059.007 JavaScriptT1069.002 Domain GroupsT1070 Indicator RemovalT1070.004 File DeletionT1070.006 TimestompT1071.001 Web ProtocolsT1072 Software Deployment ToolsT1074.001 Local Data StagingT1082 System Information DiscoveryT1083 File and Directory DiscoveryT1087.002 Domain AccountT1091 Replication Through Removable MediaT1095 Non-Application Layer ProtocolT1102 Web ServiceT1105 Ingress Tool TransferT1106 Native APIT1119 Automated CollectionT1129 Shared ModulesT1140 Deobfuscate/Decode Files or InformationT1176.002 IDE ExtensionsT1203 Exploitation for Client ExecutionT1204.001 Malicious LinkT1204.002 Malicious FileT1205 Traffic SignalingT1218.004 InstallUtilT1218.005 MshtaT1219.001 IDE TunnelingT1219.002 Remote Desktop SoftwareT1505.003 Web ShellT1518 Software DiscoveryT1546.003 Windows Management Instrumentation Event SubscriptionT1547.001 Registry Run Keys / Startup FolderT1553.002 Code SigningT1557 Adversary-in-the-MiddleT1560.001 Archive via UtilityT1560.003 Archive via Custom MethodT1564.001 Hidden Files and DirectoriesT1566.001 Spearphishing AttachmentT1566.002 Spearphishing LinkT1567.002 Exfiltration to Cloud StorageT1572 Protocol TunnelingT1573.001 Symmetric CryptographyT1574.001 DLLT1574.005 Executable Installer File Permissions WeaknessT1583.001 DomainsT1583.006 Web ServicesT1585.002 Email AccountsT1586.002 Email AccountsT1587.001 MalwareT1588.002 ToolT1588.003 Code Signing CertificatesT1588.004 Digital CertificatesT1593 Search Open Websites/DomainsT1598.003 Spearphishing LinkT1608 Stage CapabilitiesT1608.001 Upload MalwareT1622 Debugger EvasionT1654 Log EnumerationT1678 Delay Execution

Software

23 malware/tools attributed to this actor.

MimikatzPoisonIvyPlugXChina ChopperCobalt StrikeImpacketAdFindNBTscanShadowPadWevtutilRCSessionBOOKWORMStarProxyPUBLOADHIUPANSplatDropperPAKLOGSplatCloakCorKLOGCLAIMLOADERCANONSTAGERSTATICPLUGINTONESHELL

Related corpus activity

10,454 indicators EXHIBIT techniques this actor uses. This is a shared-technique signal, not a first-party attribution to Mustang Panda.

IndicatorTypeFamilySevSrc
cve-2023-44976cveransomware852
cve-2026-1969cve851
cve-2025-68670cve852
cve-2026-3102cve853
cve-2025-34117cve851
cve-2021-29441cve851
cve-2026-22584cve852
cve-2025-11837cve852
cve-2025-34054cve854
cve-2014-2321cve851
cve-2020-22653cve852
cve-2025-2492cve852
cve-2017-18377cve851
cve-2021-25646cve851
cve-2025-66478cve852
cve-2025-0921cve852
cve-2021-27076cve851
cve-2013-3307cve852
cve-2016-5681cve852
cve-2016-15047cve854
cve-2024-1781cve851
cve-2018-8007cve851
cve-2021-4045cve851
cve-2020-17456cve851
cve-2022-47945cve851
cve-2020-22658cve852
cve-2025-23304cve852
cve-2026-4368cveransomware851
cve-2013-7471cve851
cve-2026-0740cve851

Showing the top 30 by severity of 10,454.