Also known as: Bronze President, active since 2012, BRONZE PRESIDENT, HoneyMyte, tracked as, Mustang Panda, Stately Tarurus
RedDelta first gained prominence through targeted campaigns against government, defense, finance, maritime, aviation, energy, healthcare and think‑tank organizations across China, Taiwan, Vietnam, the United States, Russia, Australia, India, Pakistan, Ukraine, Italy, Brazil and Japan. The group’s operating profile is consistent with a well-funded state actor that blends traditional spearphishing techniques—both attachments and links—with advanced client‑side exploitation such as the Microsoft Office CVE‑2017‑0199 vulnerability and specially crafted GrimResource MSC files. Once inside, RedDelta leverages the PlugX backdoor to establish persistent footholds. It frequently uses LNK file abuse for execution and manipulates system attributes—creating hidden RECYCLE.BIN folders on removable media, altering timestamps and masquerading binaries as legitimate PlugX installers—to evade detection. Data staging is performed in password‑protected RAR archives using WinRAR’s rar.exe before exfiltration over encrypted channels. RedDelta routinely stages malware on adversary‑controlled domains and cloud storage (e.g., Google Drive) and routes command‑and‑control traffic through the Cloudflare CDN to obfuscate its infrastructure. The actor also employs legitimate services (SMTP2Go, custom mail accounts) for phishing campaigns and validates delivery with tracking pixels. Operationally, RedDelta adapts its target selection in response to geopolitical shifts, expanding from Southeast Asian NGOs and Catholic institutions during the 2021 Vatican–CCP talks to European governmental bodies after 2022. Its attack patterns display a deliberate pacing—periods of reconnaissance followed by high‑volume infection bursts—suggesting a well‑coordinated, long‑term espionage mandate.
Targeted Sectors
Targeted Countries / Regions
Executive Summary
RedDelta, operating under the alias Mustang Panda among others, is a Chinese state-sponsored espionage group active since at least 2019 that targets government, defense and NGO entities across Europe, Southeast Asia and the U.S. It deploys a sophisticated PlugX‑based infection chain using spearphishing, Office file exploits (e.g., CVE‑2017‑0199) and cloud-hosted staging to exfiltrate data. The group shifts its focus in response to geopolitical events, expanding attacks on European diplomatic bodies after Russia’s invasion of Ukraine and previously targeting the Vatican during CCP negotiations.
Goals & Targeting
RedDelta’s strategic objectives revolve around gathering politically sensitive intelligence from state and quasi‑state actors, research institutions, NGOs, and religious bodies to support Chinese national interests. The group focuses on entities that can provide insights into foreign policy decisions, security collaborations or economic developments beyond its borders. By targeting a mix of governmental and non‑governmental organizations—especially those involved in diplomacy, finance, maritime security, energy infrastructure and religious affairs—RedDelta seeks to harvest strategic data while maintaining operational stealth through tailored phishing lures and covert exfiltration channels.
Enhanced Description
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
RedDelta’s campaigns have been characterized by adaptive targeting that reflects shifting geopolitical contexts. Since 2019, the group has maintained a consistent presence in Southeast Asia (Myanmar and Vietnam), while expanding to European governments and NGOs post‑2022 following Russia’s invasion of Ukraine. Attack bursts often correlate with high‑profile diplomatic events—such as CCP–Vatican talks in 2021—during which the actor intensifies phishing efforts against religious and NGO institutions. Operations are typically executed through cloud staging, sophisticated delivery lures, and hardened command‑and‑control channels routed via Cloudflare, enabling rapid scalability while preserving attribution ambiguity. The actor shows a preference for exploiting known Office vulnerabilities or creating custom malicious MSC files, suggesting a blend of opportunistic and development resources. RedDelta’s persistence mechanisms—particularly China Chopper web shells and PlugX backdoors—are routinely refreshed, indicating continuous support and evolution from its sponsoring nation‑state apparatus.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
Attribution confidence to a Chinese state‑sponsored organization is high based on the actor’s sustained use of known PlugX variants, Office exploitation tactics and public statements linking the group to China. Confidence in specific campaign dates, victim lists, and exact infrastructure usage remains moderate due to limited publicly available telemetry and frequent changes in domains and cloud hosting services. There are gaps regarding the group's internal structure, long‑term operational planning, and whether all observed activities share a single command architecture.
No campaigns linked yet.
No observed data linked yet.
46
Techniques
52
Tools
0
Campaigns
39
IOCs
0
Observed Data
12
Tactics