Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors Camaro Dragon

Also known as: Mustang Panda, Earth Preta, Stately Taurus, BRONZE PRESIDENT, Bronze President, TA416, Red Delta, LuminousMoth, Twill Typhoon, Polaris, tracked as, BASIN, Red Lich, Temp.Hex, manufacturing, Storm-1789, has been targeting individuals, organizations in the software, IT, education, APT36, ProjectM, Mythic Leopard, defense, aerospace sectors using cross, BRONZE VINEWOOD, Judgment Panda, Zirconium, HoneyMyte, Greece, the Netherland, Mango Sandstorm, Tactical RMM, APT44, Strontium, Fancy Bear, Carbon Spider, Elbrus, RedDelta, Luminous Moth, ZIRCONIUM, JUDGMENT PANDA, Red keres, Violet Typhoon, TA412, TIDE CASTLE, Onyx Sleet, Earth Karkaddan, Boggy Serpens, Seashell Blizzard, Sangria Tempest

Description

In early 2023, the Check Point Incident Response Team (CPIRT) team investigated a malware incident at a European healthcare institution involving a set of tools mentioned in the Avast report in late 2022. The incident was attributed to Camaro Dragon, a Chinese-based espionage threat actor whose activities overlap with activities tracked by different researchers as Mustang Panda and LuminousMoth, whose focus is primarily on Southeast Asian countries and their close peers.

Goals & Targeting

Targeted Sectors

Government
Defense
Financial services
Telecommunications
Education
Critical infrastructure
Manufacturing
Transportation
Pharmaceutical
Aerospace
Aviation
Construction
Energy
Think tank
Non profit
Maritime
Healthcare
Information technology
Utilities
Mining
Nuclear

Targeted Countries / Regions

CN
US
TW
PK
UA
RU
KR
IN
VN
AU
IL
TR
EG
IT
BY

AI Analysis

· 1 week ago

Executive Summary

Camaro Dragon is a Chinese-based threat actor suspected to be involved in espionage activities. Linked to Mustang Panda and LuminousMoth, Camaro Dragon focuses on Southeast Asian countries and their neighboring regions. The group has been observed targeting healthcare institutions with malware, indicating a focus on data theft or intelligence gathering.

Goals & Targeting

Camaro Dragon's strategic objectives appear to be centered on intelligence gathering and espionage, likely targeting sectors with sensitive information such as healthcare, government, and financial institutions. The group's targeting of Southeast Asian countries suggests a regional focus, possibly tied to geopolitical interests or the collection of information relevant to these regions.

Enhanced Description

Camaro Dragon is a cyber threat actor believed to be based in China, involved in espionage activities targeting primarily Southeast Asian countries and their close peers. The group's activities have been linked by researchers to Mustang Panda and LuminousMoth, suggesting possible overlaps in operations or affiliations. In early 2023, the Check Point Incident Response Team (CPIRT) investigated a malware incident at a European healthcare institution involving tools mentioned in an Avast report from late 2022. This incident was attributed to Camaro Dragon, highlighting their focus on sensitive sectors like healthcare for potential data exfiltration or espionage activities.

Key Capabilities

  • Malware development and deployment
  • Spear-phishing campaigns
  • Data exfiltration techniques

MITRE ATT&CK Tactics

Collection
Exfiltration
Persistence

ATT&CK Techniques

T1567.001
T1055
T1215

Software / Tooling

Custom malware (as reported in the Avast and Check Point reports)
Phishing tools

Campaigns & Victims

Camaro Dragon's campaigns appear to focus on specific industries, such as healthcare, suggesting a strategic approach to target high-value information. The group's operational tempo is likely tied to their links with other Chinese-based actors, indicating potential state-sponsored activity. Notable past operations include the 2022-2023 targeting of Southeast Asian and European institutions via malware and spear-phishing attacks.

IOC Patterns

  • Spear-phishing emails with malicious attachments
  • Malware distribution through compromised websites or documents
  • Scheduled task-based persistence mechanisms

Recommended Actions

  • Implement robust email filtering to detect phishing attempts
  • Monitor network traffic for indicators of data exfiltration
  • Conduct regular employee training on social engineering attacks
  • Use endpoint detection and response (EDR) solutions to identify malicious activity

Suggested Tags

APT
espionage
healthcare-sector
Southeast-Asia

Confidence Assessment

High confidence in the general characterization of Camaro Dragon as an espionage-focused threat actor due to its linkage with Mustang Panda and LuminousMoth. However, specific TTPs and exact modus operandi remain unclear without further data.

ATT&CK Techniques

Command & Control
1 technique
Exfiltration
1 technique

Software / Tooling

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

Domain 13 Filename 3 IPv4 Address 4

References

  1. ics-cert.kaspersky.com — Cited by web research for: manufacturing
  2. unit42.paloaltonetworks.com — Cited by web research for: RedDelta
  3. apt.etda.or.th — Cited by web research for: ShadowPad
  4. cloud.google.com — Cited by web research for: Botnets
  5. research.checkpoint.com — Cited by web research for: schtasks
  6. research.checkpoint.com — Cited by web research for: RC4 encryption

Intel Summary

3

Techniques

44

Tools

0

Campaigns

40

IOCs

0

Observed Data

3

Tactics

Tags

APT
Healthcare Targeting
espionage
healthcare-sector
Southeast-Asia

Details

Type
Unknown
Primary Motivation
Espionage
Country of Origin
C
Confidence
60%
Added
May 26, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.