Mustang Panda
MITRE ATT&CK: G0129 View on attack.mitre.org
Aliases: TA416, RedDelta, BRONZE PRESIDENT, STATELY TAURUS, FIREANT, CAMARO DRAGON, EARTH PRETA, HIVE0154, TWILL TYPHOON, TANTALUM, LUMINOUS MOTH, UNC6384, TEMP.Hex, Red Lich, ClumsyToad, HoneyMyte, TEMP.HEX, BASIN, Earth Preta, Stately Taurus, LuminousMoth, Polaris, Twill Typhoon, Mustang Panda, MUSTANG PANDA
- First seen
- 2012-01-01 00:00:00
- Origin
- CN
- Primary motivation
- espionage
- Sophistication
- advanced
- Resource level
- government
- Actor type
- Espionage
- Related IoCs
- 59 (48 malicious)
- Last IoC activity
- 2026-09-01 16:33:36
- Profile updated
- 2026-07-07 11:48:24
Targeted industries: government-and-public-sector education-and-nonprofits technology-and-telecommunications
Targeted regions: country_code:us country_code:cn country_code:ru country_code:mn country_code:mm country_code:pk country_code:vn
Context
Mustang Panda is a China-based cyber espionage threat actor that has been conducting operations since at least 2012. Mustang Panda has been known to use tailored phishing lures and decoy documents to deliver malicious payloads. Mustang Panda has targeted government, diplomatic, and non-governmental organizations, including think tanks, religious institutions, and research entities, across the United States, Europe, and Asia, with notable activity in Russia, Mongolia, Myanmar, Pakistan, and Vietnam.
Recent IoC activity
48 malicious indicators in Maltiverse are attributed to Mustang Panda (G0129). The 20 most recently updated:
Detection coverage
- 174 YARA rules
- 826 Sigma rules
Malware & tools used
- System Network Configuration Discovery (attack-pattern)
- Upload Malware (attack-pattern)
- Web Services (attack-pattern)
- Windows Management Instrumentation (attack-pattern)
- Symmetric Cryptography (attack-pattern)
- Search Open Websites/Domains (attack-pattern)
- Malicious Link (attack-pattern)
- Network Service Discovery (attack-pattern)
- Deobfuscate/Decode Files or Information (attack-pattern)
- System Network Connections Discovery (attack-pattern)
- Visual Basic (attack-pattern)
- IDE Tunneling (attack-pattern)
- Exfiltration to Cloud Storage (attack-pattern)
- Scheduled Task (attack-pattern)
- Domain Account (attack-pattern)
- Spearphishing Link (attack-pattern)
- Delay Execution (attack-pattern)
- Hidden Files and Directories (attack-pattern)
- Mshta (attack-pattern)
- Dynamic API Resolution (attack-pattern)
- Email Accounts (attack-pattern)
- Remote Desktop Software (attack-pattern)
- OS Credential Dumping (attack-pattern)
- DCSync (attack-pattern)
- InstallUtil (attack-pattern)
Related threat objects
- RedDelta (threat-actor)
Reports & references
- cloud.google.com — Updated Cyber Threat Actor Naming System (report)
- pwc.co.uk — Pwc Cyber Threats 2020 A Year In Retrospect (report)
- bsi.bund.de — Aktive Apt Gruppen Node (report)
- CrowdStrike — Report2020Crowdstrikeglobalthreatreport (report)
- services.google.com — Google Fog Of War Research Report (report)
- cfr.org — Mustang Panda (report)
- CrowdStrike — Meet Crowdstrikes Adversary Of The Month For June Mustang Panda (report)
- secureworks.com — Bronze President (report)
- darkreading.com — Chinese Apt Bronze President Spy Campaign Russian Military (report)
- pwc.co.uk — Cyber Threats 2019 Retrospect (report)
- Trend Micro — Earth Preta Spear Phishing Governments Worldwide (report)
- proofpoint.com — Ta416 Goes Ground And Returns Golang Plugx Malware Loader (report)
- proofpoint.com — Good Bad And Web Bug Ta416 Increases Operational Tempo Against European (report)
- Palo Alto Unit 42 — Stately Taurus Targets Philippines Government Cyberespionage (report)
- Microsoft — Rw1Afyw (report)
- jsac.jpcert.or.jp — Jsac2023 2 Lt4 (report)
- thecyberwire.com — Notes (report)
- research.checkpoint.com — The Dragon Who Sold His Camaro Analyzing Custom Router Implant (report)
- cloud.google.com — Prc Nexus Espionage Targets Diplomats (report)
- raw.githubusercontent.com — Microsoftmapping (report)
- Microsoft — Microsoft Threat Actor Naming (report)
- blog.cloudflare.com — 2026 Threat Report (report)
- MITRE ATT&CK — G0129 (report)
- blog.eclecticiq.com — Mustang Panda Apt Group Uses European Commission Themed Lure To Deliver Plugx Malware (report)
- Cisco Talos — Mustang Panda Targets Europe (report)
Attributed from
- RedDelta Modified PlugX Infection Chain Operations (campaign)
- RedDelta Updated PlugX Infection Chain (Deprecated) (campaign)
External references
- mitre-attack — G0129
- Cloudflare 2026 Threat Report New Threat Actors March 2026
- EARTH PRETA
- FIREANT
- ClumsyToad
- Mustang Panda
- UNC6384
- TEMP.Hex
- CAMARO DRAGON
- HIVE0154
- TWILL TYPHOON
- TANTALUM
- LUMINOUS MOTH
- STATELY TAURUS
- TA416
- Red Lich
- RedDelta
- BRONZE PRESIDENT
- Eset PlugX Korplug Mustang Panda March 2022
- Anomali MUSTANG PANDA October 2019