Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors RedDelta

Also known as: Bronze President, active since 2012, BRONZE PRESIDENT, HoneyMyte, tracked as, Mustang Panda, Stately Tarurus

Description

RedDelta first gained prominence through targeted campaigns against government, defense, finance, maritime, aviation, energy, healthcare and think‑tank organizations across China, Taiwan, Vietnam, the United States, Russia, Australia, India, Pakistan, Ukraine, Italy, Brazil and Japan. The group’s operating profile is consistent with a well-funded state actor that blends traditional spearphishing techniques—both attachments and links—with advanced client‑side exploitation such as the Microsoft Office CVE‑2017‑0199 vulnerability and specially crafted GrimResource MSC files. Once inside, RedDelta leverages the PlugX backdoor to establish persistent footholds. It frequently uses LNK file abuse for execution and manipulates system attributes—creating hidden RECYCLE.BIN folders on removable media, altering timestamps and masquerading binaries as legitimate PlugX installers—to evade detection. Data staging is performed in password‑protected RAR archives using WinRAR’s rar.exe before exfiltration over encrypted channels. RedDelta routinely stages malware on adversary‑controlled domains and cloud storage (e.g., Google Drive) and routes command‑and‑control traffic through the Cloudflare CDN to obfuscate its infrastructure. The actor also employs legitimate services (SMTP2Go, custom mail accounts) for phishing campaigns and validates delivery with tracking pixels. Operationally, RedDelta adapts its target selection in response to geopolitical shifts, expanding from Southeast Asian NGOs and Catholic institutions during the 2021 Vatican–CCP talks to European governmental bodies after 2022. Its attack patterns display a deliberate pacing—periods of reconnaissance followed by high‑volume infection bursts—suggesting a well‑coordinated, long‑term espionage mandate.

Goals & Targeting

Targeted Sectors

Government
Defense
Non profit
Financial services
Maritime
Aviation
Energy
Healthcare
Think tank

Targeted Countries / Regions

CN
TW
VN
US
RU
AU
IN
PK
UA
IT
BR
JP

AI Analysis

Grounded in web research
· analyzed in 4 chunks · 21 hours ago

Executive Summary

RedDelta, operating under the alias Mustang Panda among others, is a Chinese state-sponsored espionage group active since at least 2019 that targets government, defense and NGO entities across Europe, Southeast Asia and the U.S. It deploys a sophisticated PlugX‑based infection chain using spearphishing, Office file exploits (e.g., CVE‑2017‑0199) and cloud-hosted staging to exfiltrate data. The group shifts its focus in response to geopolitical events, expanding attacks on European diplomatic bodies after Russia’s invasion of Ukraine and previously targeting the Vatican during CCP negotiations.

Goals & Targeting

RedDelta’s strategic objectives revolve around gathering politically sensitive intelligence from state and quasi‑state actors, research institutions, NGOs, and religious bodies to support Chinese national interests. The group focuses on entities that can provide insights into foreign policy decisions, security collaborations or economic developments beyond its borders. By targeting a mix of governmental and non‑governmental organizations—especially those involved in diplomacy, finance, maritime security, energy infrastructure and religious affairs—RedDelta seeks to harvest strategic data while maintaining operational stealth through tailored phishing lures and covert exfiltration channels.

Enhanced Description

Key Capabilities

  • Spearphishing attachments and links that incorporate Office exploits (CVE‑2017‑0199) and custom MSC files
  • Deployment of a PlugX backdoor for persistence, lateral movement and data exfiltration
  • Use of password-Protected RAR archives staged with WinRAR (rar.exe) as temporary storage before exfiltration
  • Obfuscation tactics such as hidden RECYCLE.BIN folders on removable media, altered file timestamps and masqueraded executables
  • Exploitation of LNK files to execute malicious payloads while displaying innocuous PDF icons
  • Leveraging legitimate email marketing services (SMTP2Go) and custom mail accounts for phishing campaigns
  • Staging malware on adversary‑controlled domains and cloud storage, including Google Drive links
  • Routing command‑and‑control traffic via the Cloudflare CDN to obfuscate infrastructure
  • Active Directory reconnaissance using AdFind and SharpNBTScan
  • Process discovery using tasklist, TONESHELL and other post‑exploitation tools (Impacket, RemCom)

MITRE ATT&CK Tactics

Initial Access
Execution
Discovery
Defense Evasion
Collection
Persistence
Command and Control

ATT&CK Techniques

T1566.001
T1566.002
T1203
T1074
T1083
T1036
T1078
T1082
T1057
T1087
T1016.001
T1135
T1557
T1583
T1547
T1564
T1119
T1071
T1218.007
T1140
T1218
T1560
T1090
T1059
T1036.004
T1586
T1102
T1608
T1480
T1204
T1048
T1678
T1566
T1001
T1574
T1027
T1546
T1553
T1573
T1095
T1585
T1588
T1622
T1564.001
T1587
T1204.001

Software / Tooling

PlugX
WinRAR (rar.exe)
TONESShell
RemCom
Impacket
SMTP2Go
AdFind
SharpNBTScan
China Chopper web shells
Visual Studio Code (code.exe tunneling)
Poison Ivy
Cobalt Strike
BOOKWORM
ShadowPad
Mimikatz
NBTscan
Web Shells
Beacon
Nexus
PowerShell
mshta

Campaigns & Victims

RedDelta’s campaigns have been characterized by adaptive targeting that reflects shifting geopolitical contexts. Since 2019, the group has maintained a consistent presence in Southeast Asia (Myanmar and Vietnam), while expanding to European governments and NGOs post‑2022 following Russia’s invasion of Ukraine. Attack bursts often correlate with high‑profile diplomatic events—such as CCP–Vatican talks in 2021—during which the actor intensifies phishing efforts against religious and NGO institutions. Operations are typically executed through cloud staging, sophisticated delivery lures, and hardened command‑and‑control channels routed via Cloudflare, enabling rapid scalability while preserving attribution ambiguity. The actor shows a preference for exploiting known Office vulnerabilities or creating custom malicious MSC files, suggesting a blend of opportunistic and development resources. RedDelta’s persistence mechanisms—particularly China Chopper web shells and PlugX backdoors—are routinely refreshed, indicating continuous support and evolution from its sponsoring nation‑state apparatus.

IOC Patterns

  • Password‑protected RAR archives used for data staging
  • Hidden RECYCLE.BIN folders on USB drives
  • Altered file attributes (hidden/system)
  • Modified timestamps derived from the export address table
  • Masqueraded executables disguised as legitimate PlugX installers
  • LNK files configured to display a PDF icon for malicious execution
  • URL‑based phishing links
  • Google Drive download URLs
  • Malicious JavaScript downloader scripts
  • Tracking pixel URLs
  • Spearfishing attachment delivery
  • Spearfishing link emails targeting government/NGO entities
  • Malicious MSC file downloads from Azure‑hosted sites
  • Windows LNK exploitation for code execution
  • User agent fingerprinting of victim OS
  • Cloudflare CDN used to proxy C2 traffic
  • Cloud storage staging of malware

Recommended Actions

  • Patch Microsoft Office to mitigate CVE‑2017‑0199 and related file‑format exploits.
  • Monitor and block traffic to known malicious C2 domains used by Mustang Panda.
  • Implement stricter controls on the use of legitimate email marketing services such as SMTP2Go for outbound phishing.
  • Detect and block the creation of hidden folders (e.g., RECYCLE.BIN) on removable drives.
  • Deploy tools that detect altered file attributes, timestamps, or masquerading tactics.
  • Enable detection of LNK abuse through application whitelisting and script analysis.
  • Apply granular monitoring for RAR/ZIP attachments in email gateways to flag potential data staging.
  • Use endpoint detection platforms to identify WinRAR execution patterns associated with exfiltration.
  • Implement multi‑factor authentication and strengthen user security awareness training to guard against phishing emails.
  • Deploy email filtering solutions that block malicious attachments and URLs, including Google Drive links.
  • Enforce EDR monitoring to detect suspicious process discovery activity (tasklist/Toneshell) and anomalous use of Visual Studio Code tunnels.
  • Block known adversary‑controlled domains and cloud file hosting services used for staging malware.
  • Monitor network traffic for unusual JavaScript redirects and tracking pixels that indicate successful delivery.
  • Implement email filtering and sandboxing to block spearphishing attachments and links.
  • Monitor and restrict execution of MSC and LNK files from untrusted sources.
  • Deploy EDR solutions with signatures for PlugX, Poison Ivy, and Cobalt Strike.
  • Analyze outbound traffic via Cloudflare CDN to detect anomalous patterns.
  • Provide user awareness training on phishing targeting diplomatic and NGO organizations.
  • Strengthen network defenses and security measures for religious and non‑governmental organizations to mitigate attacks from state‑sponsored threat actors like RedDelta.

Suggested Tags

RedDelta
Mustang Panda
PlugX
Spearphishing Attachment
Spearphishing Link
Client‑Side Exploitation
Data Staging
Masquerading
USB Abuse
WinRAR
Impacket
TONESShell
Phishing
Malware Delivery
Process Discovery
Active Directory Reconnaissance
Web Shell Persistence
Tracking Pixel
State-sponsored
China
Poison Ivy
Cobalt Strike
Cloudflare
religious bodies
NGO targeting
Government
Defense

Confidence Assessment

Attribution confidence to a Chinese state‑sponsored organization is high based on the actor’s sustained use of known PlugX variants, Office exploitation tactics and public statements linking the group to China. Confidence in specific campaign dates, victim lists, and exact infrastructure usage remains moderate due to limited publicly available telemetry and frequent changes in domains and cloud hosting services. There are gaps regarding the group's internal structure, long‑term operational planning, and whether all observed activities share a single command architecture.

ATT&CK Techniques

Credential Access
1 technique
Defense impairment
1 technique
Privilege Escalation
1 technique

Software / Tooling

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

References

  1. www.recordedfuture.com — Cited by web research for: BRONZE PRESIDENT
  2. attack.mitre.org — Cited by web research for: Mustang Panda
  3. www.recordedfuture.com — Cited by web research for: India
  4. https://attack.mitre.org/campaigns/C0047/ — Cited by AI analysis.
  5. https://www.recordedfuture.com/research/reddelta-chinese-state-sponsored-group-targets-mongolia-taiwan-southeast-as — Cited by AI analysis.

Intel Summary

46

Techniques

52

Tools

0

Campaigns

39

IOCs

0

Observed Data

12

Tactics

Tags

APT
Backdoor / C2
Government Targeting
RedDelta
Mustang Panda
PlugX
Spearphishing Attachment
Spearphishing Link
Client‑Side Exploitation
Data Staging
Masquerading
USB Abuse
WinRAR
Impacket
TONESShell
Phishing
Malware Delivery
Process Discovery
Active Directory Reconnaissance
Web Shell Persistence
Tracking Pixel
State-sponsored
China
Poison Ivy
Cobalt Strike
Cloudflare
religious bodies
NGO targeting
Government
Defense

Details

Type
Unknown
Primary Motivation
Espionage
Country of Origin
China (CN)
Confidence
60%
Added
May 26, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.