Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors Mustang Panda

Also known as: HoneyMyte, Temp.Hex, BRONZE PRESIDENT, Red Lich, BASIN, Earth Preta, TA416, Stately Taurus, LuminousMoth, Polaris, TANTALUM, Twill Typhoon, BASIN CASTLE, RedDelta, FIREANT, CAMARO DRAGON, HIVE0154, LUMINOUS MOTH, UNC6384, ClumsyToad, active since 2012, other aliases, drops updated Toneshell backdoor, several other aliases, APT28, first identified in 2014, 0mid16B, Cobalt Gang, Slayer Kitten, GOLD HERON, Phantom Panda, Alloy Taurus, Granite Typhoon, Callisto, SEABORGIUM, TA446, Evil Corp, the Latrodectus downloader, the Lotus loader family, Gold Southfield, SideWinder, APT-C-17, Rattlesnake, APT39, Chafer, Sodinokibi, first observed in 2019, APT37, Selective Pisces, is a sophisticated, governments, MuddyWater, Seedworm, TEMP.Zagros, Mercury, APT26, Volt Typhoon, Bronze Silhouette, DEV-0391, COLDRIVER, GOSSAMER BEAR, BlueCharlie, Star Blizzard, TAG-53, IRON FRONTIER, UNC4057, Blue Callisto, COLD RELIC, ALPHV, Gleaming Pisces, BokBot, PlayCrypt, Turla, Snake, Uroboros, DEV-0832, Vanilla Tempest, is a notorious ransomware, APT15, Ke3chang, Red Delta, APT27, Winnti, the threat actor, NoFive, Sandworm Team, Operation Cleaver, Shell Crew, WebMasters, KungFu Kittens, PinkPanther, a separate entity, VOLTZITE, for follow-on operations, Stately Tarurus, the ALPHV Ransomware Group, ALPHV Blackcat, Jumpy Pisces, Comment Crew, MenuPass, Red Apollo, Stone Panda, Gothic Panda, UPS Team, Pirate Panda, Buckeye, Reaper, ScarCruft

Description

**Targets:** Mining sector in Mongolia, private individuals |=| gathering geo-political and economic intelligence. **Toolset/Malware:** PlugX

Goals & Targeting

Targeted Sectors

Government
Ngo
Financial services
Defense
Telecommunications
Healthcare
Critical infrastructure
Education
Manufacturing
Non profit
Energy
Media
Aviation
Think tank
Hospitality
Aerospace
Pharmaceutical
Maritime
Retail
Gaming
Transportation
Utilities
Information technology
Legal services
Mining
Chemical
Nuclear
Entertainment
Oil gas
Construction

Targeted Countries / Regions

British Indian Ocean Territory
India
CN
US
RU
IN
IR
VN
TW
AU
PK
UA
JP
IL
GB
KR
SA
AE
KP
SG
DE
TR
BY
BR
MX
ES
PL
CA
RO
FR
NG
IT
LB
AZ
KZ

AI Analysis

· 2 weeks ago

Executive Summary

Mustang Panda (also known as TA416) is a sophisticated nation-state threat actor primarily involved in espionage activities targeting government and non-governmental organizations (NGOs). The group is known for its use of PlugX malware and other tools to gather geopolitical and economic intelligence, leveraging various tactics including spearphishing and persistence techniques.

Goals & Targeting

Mustang Panda's strategic goals center around gathering geo-political and economic intelligence, particularly from government entities and NGOs. Their targeting profile suggests a focus on sectors that hold sensitive information valuable for national security and global strategy. The group likely operates with authorization from a state sponsor, making their activities politically motivated rather than financially driven.

Enhanced Description

Mustang Panda, also referred to by aliases such as TA416 or Stately Taurus, is a cyberespionage group with significant operational capabilities. The actor primarily targets government agencies and NGOs, focusing on collecting strategic intelligence that can influence geopolitical dynamics. Their tactics include the use of malicious software like PlugX, which enables persistence, credential theft, and data exfiltration. The group has demonstrated a strong technical proficiency, employing a wide range of attack techniques to achieve their objectives.

Key Capabilities

  • PlugX malware
  • Cobalt Strike
  • China Chopper
  • HIUPAN
  • ShadowPad

MITRE ATT&CK Tactics

Lateral Movement
Exfiltration
Credential Access
Defense Evasion
Discovery
Collection
Impact
Initial Access
Operations Security

ATT&CK Techniques

T1053.005
T1560.001
T1087.002
T1003
T1059.007
T1074.001
T1036.007
T1560.003
T1036.005
T1036.008
T1587.001
T1204.002
T1573.001
T1566.002
T1218.004
T1070.006
T1572
T1505.003
T1583.001
T1205
T1070
T1083
T1049
T1102
T1218.005
T1027.012
T1654
T1583.006
T1041

Software / Tooling

PlugX
Cobalt Strike
China Chopper

Campaigns & Victims

Mustang Panda has been involved in numerous campaigns targeting government and NGO sectors. Their operations often involve long-term espionage efforts, utilizing persistence techniques to maintain access to networks over extended periods. The group is known to leverage malicious software for data exfiltration and credential theft, indicating a focus on stealing sensitive information that could impact national security.

IOC Patterns

  • Use of PlugX malware
  • Cobalt Strike-based attacks
  • Malicious activity leveraging China Chopper

Recommended Actions

  • Implement robust email filtering to detect spearphishing attempts.
  • Monitor for T1053.005 (Scheduled Task) and T1003 (OS Credential Dumping) activity.
  • Segment networks to limit lateral movement in case of a breach.
  • Regularly update software to mitigate exploitation vectors.

Suggested Tags

APT
espionage
government
NGO

Confidence Assessment

High confidence in the actor's identity and toolset, with some gaps in specific campaign details and exact country affiliations. Additional information on their recent operational patterns would enhance understanding.

ATT&CK Techniques

Collection
6 techniques
Command & Control
12 techniques
Credential Access
5 techniques
Discovery
13 techniques
Execution
13 techniques
Exfiltration
7 techniques
Initial Access
3 techniques
Persistence
4 techniques
Resource Development
15 techniques
Stealth
23 techniques

Software / Tooling

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

References

  1. Cloudflare 2026 Threat Report New Threat Actors March 2026 — Cloudflare. (2026, March 3). Introducing the 2026 Cloudflare Threat Report. Retrieved April 18, 2026.
  2. Eset PlugX Korplug Mustang Panda March 2022 — Alexandre Cote Cyr. (2022, March 23). Mustang Panda’s Hodur: Old tricks, new Korplug variant. Retrieved September 9, 2025.
  3. Anomali MUSTANG PANDA October 2019 — Anomali Threat Research. (2019, October 7). China-Based APT Mustang Panda Targets Minority Groups, Public and Private Sector Organizations. Retrieved April 12, 2021.
  4. Cisco Talos MUSTANG PANDA PLUGX PUBLOAD MAY 2022 — Asheer Malhotra, Jungsoo An, Kendall Mc. (2022, May 5). Mustang Panda deploys a new wave of malware targeting Europe. Retrieved August 4, 2025.
  5. Broadcom — Broadcom Protection Bulletins. (2025, February 20). Bookworm malware linked to Fireant (aka Stately Tarurus) activity observed in Southeast Asia. Retrieved July 21, 2025.
  6. HorseShell — Cohen, Itay. Madej, Radoslaw. Threat Intelligence Team. (2023, May 16). THE DRAGON WHO SOLD HIS CAMARO: ANALYZING CUSTOM ROUTER IMPLANT. Retrieved December 26, 2023.
  7. Secureworks BRONZE PRESIDENT December 2019 — Counter Threat Unit Research Team. (2019, December 29). BRONZE PRESIDENT Targets NGOs. Retrieved April 13, 2021.
  8. CSIRT CTI MUSTANG PANDA PUBLOAD TONESHELL JAN 2024 — CSIRT CTI. (2024, January 23). Stately Taurus Targets Myanmar Amidst Concerns over Military Junta’s Handling of Rebel Attacks. Retrieved August 4, 2025.
  9. DOJ Affidavit Search and Seizure PlugX December 2024 — DOJ. (2024, December 20). Mag. No. 24-mj-1387 AFFIDAVIT IN SUPPORT OF AN APPLICATION FOR A NINTH SEARCH AND SEIZURE WARRANT- IN THE MATTER OF THE SEARCH AND SEIZURE OF COMPUTERS IN THE UNITED STATES INFECTED WITH PLUGX MALWARE . Retrieved September 9, 2025.
  10. EclecticIQ Mustang Panda PlugX — EclecticIQ Threat Research Team. (2023, February 2). Mustang Panda APT Group Uses European Commission-Themed Lure to Deliver PlugX Malware. Retrieved September 9, 2025.
  11. IBM MUSTANG PANDA PUBLOAD CLAIMLOADER JUNE 2025 — Golo Muhr, Joshua Chung. (2025, June 23). Hive0154 aka Mustang Panda shifts focus on Tibetan community to deploy Pubload backdoor. Retrieved August 4, 2025.
  12. 2025_IBM_PUBLOAD_TONESHELL_HIUPAN_CLAIMLOADER_MUSTANG PANDA — Golo Muhr, Joshua Chung. (2025, May 15). Hive0154 targeting US, Philippines, Pakistan and Taiwan in suspected espionage campaign. Retrieved August 4, 2025.
  13. Recorded Future REDDELTA July 2020 — Insikt Group. (2020, July 28). CHINESE STATE-SPONSORED GROUP ‘REDDELTA’ TARGETS THE VATICAN AND CATHOLIC ORGANIZATIONS. Retrieved April 13, 2021.
  14. ATTACKIQ MUSTANG PANDA TONESHELL March 2023 — Ken Towne, Francis Guibernau. (2023, March 23). Emulating the Politically Motivated Chinese APT Mustang Panda. Retrieved September 10, 2025.
  15. Trend Micro MUSTANG PANDA PUBLOAD HIUPAN SEPTEMBER 2024 — Lenart Bermejo, Sunny Lu, Ted Lee. (2024, September 9). Earth Preta Evolves its Attacks with New Malware and Strategies. Retrieved August 4, 2025.
  16. Palo Alto Unit42 STATELY TAURUS TONESHELL September 2023 — Lior Rochberger, Tom Fakterman, Robert Falcone. (2023, September 22). Cyberespionage Attacks Against Southeast Asian Government Linked to Stately Taurus, Aka Mustang Panda. Retrieved September 9, 2025.
  17. Crowdstrike MUSTANG PANDA June 2018 — Meyers, A. (2018, June 15). Meet CrowdStrike’s Adversary of the Month for June: MUSTANG PANDA. Retrieved April 12, 2021.
  18. Microsoft Naming Conventions Frequently Updated — Microsoft. (2025, September 8). How Microsoft names threat actors. Retrieved September 10, 2025.
  19. Trend Micro Mustang Panda Earth Preta Toneshell February 2025 — Nathaniel Morales, Nick Dai. (2025, February 18). Earth Preta Mixes Legitimate and Malicious Components to Sidestep Detection. Retrieved September 10, 2025.
  20. 2022 November_TrendMicro_Earth Preta_Toneshell_Pubload — Nick Dai, Vickie Su, Sunny Lu. (2022, November 18). Earth Preta Spear-Phishing Governments Worldwide. Retrieved August 4, 2025.
  21. Google Threat Intelligence Group MUSTANG PANDA PLUGX August 2025 — Patrick Whitsell. (2025, August 25). Deception in Depth: PRC-Nexus Espionage Campaign Hijacks Web Traffic to Target Diplomats. Retrieved September 9, 2025.
  22. Proofpoint TA416 November 2020 — Proofpoint Threat Research Team. (2020, November 23). TA416 Goes to Ground and Returns with a Golang PlugX Malware Loader. Retrieved April 13, 2021.
  23. PWC UK MUSTANG PANDA RED LICH February 2021 — PWC UK. (2021, February 28). Cyber Threats 2020: A Year in Retrospect. Retrieved October 15, 2025.
  24. Proofpoint TA416 Europe March 2022 — Raggi, M. et al. (2022, March 7). The Good, the Bad, and the Web Bug: TA416 Increases Operational Tempo Against European Governments as Conflict in Ukraine Escalates. Retrieved March 16, 2022.
  25. Unit42 Bookworm Nov2015 — Robert Falcone, Mike Scott, Juan Cortes. (2015, November 10). Bookworm Trojan: A Model of Modular Architecture. Retrieved July 21, 2025.
  26. Palo Alto Networks, Unit 42 — Robert Falcone. (2025, February 20). Stately Taurus Activity in Southeast Asia Links to Bookworm Malware. Retrieved July 21, 2025.
  27. Sophos PlugX September 2022 — Secureworks Counter Threat Unit Research Team. (2022, April 27). BRONZE PRESIDENT Targets Russian Speakers with Updated PlugX. Retrieved September 9, 2025.
  28. Sophos Mustang Panda PLUGX — Secureworks Counter Threat Unit Research Team. (2022, September 8). BRONZE PRESIDENT Targets Government Officials. Retrieved September 9, 2025.
  29. Zscaler — Sudeep Singh. (2025, April 16). Latest Mustang Panda Arsenal: ToneShell and StarProxy | P1. Retrieved July 21, 2025.
  30. Trend Micro Mustang Panda Earth Preta TONESHELL June 2023 — Sunny Lu, Vickie Su, Nick Dai. (2023, June 14). Behind the Scenes: Unveiling the Hidden Workings of Earth Preta. Retrieved September 10, 2025.
  31. BlackBerry MUSTANG PANDA October 2022 — The BlackBerry Research and Intelligence Team. (2022, October 6). Mustang Panda Abuses Legitimate Apps to Target Myanmar Based Victims. Retrieved October 14, 2025.
  32. Unit42 Chinese VSCode 06 September 2024 — Tom Fakterman. (2024, September 6). Chinese APT Abuses VSCode to Target Government in Asia. Retrieved March 24, 2025.
  33. www.huntress.com — Cited by web research for: other aliases
  34. attack.mitre.org — Cited by web research for: APT28
  35. attack.mitre.org — Cited by web research for: T1087
  36. www.sentinelone.com — Cited by web research for: PHPsert
  37. apt.etda.or.th — Cited by web research for: Nexus

Intel Summary

107

Techniques

60

Tools

0

Campaigns

40

IOCs

0

Observed Data

14

Tactics

Tags

APT
espionage
government
NGO

Details

MITRE ID
G0129
Type
Nation-State
Resource Level
Government
Primary Motivation
Espionage
Country of Origin
China (CN)
Confidence
70%
Added
Jul 21, 2026
STIX ID
intrusion-set--420ac20b-f2b9-42b8-aa1a-6d4b72895ca4
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.