Mustang Panda

MITRE ATT&CK: G0129 View on attack.mitre.org

Aliases: TA416, RedDelta, BRONZE PRESIDENT, STATELY TAURUS, FIREANT, CAMARO DRAGON, EARTH PRETA, HIVE0154, TWILL TYPHOON, TANTALUM, LUMINOUS MOTH, UNC6384, TEMP.Hex, Red Lich, ClumsyToad, HoneyMyte, TEMP.HEX, BASIN, Earth Preta, Stately Taurus, LuminousMoth, Polaris, Twill Typhoon, Mustang Panda, MUSTANG PANDA

First seen
2012-01-01 00:00:00
Origin
CN
Primary motivation
espionage
Sophistication
advanced
Resource level
government
Actor type
Espionage
Related IoCs
59 (48 malicious)
Last IoC activity
2026-09-01 16:33:36
Profile updated
2026-07-07 11:48:24

Targeted industries: government-and-public-sector education-and-nonprofits technology-and-telecommunications

Targeted regions: country_code:us country_code:cn country_code:ru country_code:mn country_code:mm country_code:pk country_code:vn

Context

Mustang Panda is a China-based cyber espionage threat actor that has been conducting operations since at least 2012. Mustang Panda has been known to use tailored phishing lures and decoy documents to deliver malicious payloads. Mustang Panda has targeted government, diplomatic, and non-governmental organizations, including think tanks, religious institutions, and research entities, across the United States, Europe, and Asia, with notable activity in Russia, Mongolia, Myanmar, Pakistan, and Vietnam.

Recent IoC activity

48 malicious indicators in Maltiverse are attributed to Mustang Panda (G0129). The 20 most recently updated:

TypeIndicatorUpdatedSources
hostname broker.emqx.io 2026-09-02 2
file sample SolidPDFCreator.dll 2026-08-23 3
file sample 1acb061ce63ee8ee172fbdf518bd261ef2c46d818ffd4b1614db6ce3daa5a885 2026-08-17 3
file sample 42e6067337ac9edd1ed6603ca8ed4f4f89520bca0995116e7095c2426b7edfe2 2026-08-16 1
file sample 941993f885957176d75f24ef3f8935ecb589bb9b445bb0d71fb18b65e61b6ee4.exe 2026-05-06 2
file sample 819f586ca65395bdd191a21e9b4f3281159f9826e4de0e908277518dba809e5b 2026-03-03 1
file sample 2c34b47ee7d271326cfff9701377277b05ec4654753b31c89be622e80d225250 2026-03-03 1
file sample f7d35cb95256513c07c262d4b03603e073e58eb4cd5fa9aac1e04ecc6e870d42 2025-12-22 1
hostname jcswcd.com 2025-12-18 2
file sample 9ce5abd02d397689d99f62dfbd2a6a396876c6629cb5db453f1dcbbc3465ac9a 2025-12-07 2
file sample bf8e512921522e49d16c638dc8d01bd0a2803a4ef019afbfc2f0941875019ea1 2025-10-02 1
file sample ba55542c6fa12865633d6d24f4a81bffd512791a6e0a9b77f6b17a53e2216659 2025-08-26 1
file sample 4547914e17c127d9b53bbc9d44de0e5b867f1a86d2e5ede828cd3188ed7fe838 2024-12-12 2
file sample ea5825fa1f39587a88882e87064caae9dd3b79f02438dc3a229c5b775b530c7d 2023-07-05 1
file sample fd0711a50c8af1dbc5c7ba42b894b2af8a2b03dd7544d20f5a887c93b9834429 2023-07-05 1
file sample ec3e491a831b4057fc0e2ebe9f43c32f1f07959b6430b323d35d6d409d2b31e4 2023-07-05 1
file sample edb5d4b454b6c7d3abecd6de7099e05575b8f28bb09dfc364e45ce8c16a34fcd 2023-07-05 1
file sample c96723a68fc939c835578ff746f7d4c5371cb82a9c0dffe360bb656acea4d6e1 2023-07-05 1
file sample ce308b538ff3a0be0dbcee753db7e556a54b4aeddbddd0c03db7126b08911fe2 2023-07-05 1
file sample bf4f8a5f75e9e5ecd752baa73abddd37b014728722ac3d74b82bffa625bf09b5 2023-07-05 1

Detection coverage

  • 174 YARA rules
  • 826 Sigma rules

Malware & tools used

  • System Network Configuration Discovery (attack-pattern)
  • Upload Malware (attack-pattern)
  • Web Services (attack-pattern)
  • Windows Management Instrumentation (attack-pattern)
  • Symmetric Cryptography (attack-pattern)
  • Search Open Websites/Domains (attack-pattern)
  • Malicious Link (attack-pattern)
  • Network Service Discovery (attack-pattern)
  • Deobfuscate/Decode Files or Information (attack-pattern)
  • System Network Connections Discovery (attack-pattern)
  • Visual Basic (attack-pattern)
  • IDE Tunneling (attack-pattern)
  • Exfiltration to Cloud Storage (attack-pattern)
  • Scheduled Task (attack-pattern)
  • Domain Account (attack-pattern)
  • Spearphishing Link (attack-pattern)
  • Delay Execution (attack-pattern)
  • Hidden Files and Directories (attack-pattern)
  • Mshta (attack-pattern)
  • Dynamic API Resolution (attack-pattern)
  • Email Accounts (attack-pattern)
  • Remote Desktop Software (attack-pattern)
  • OS Credential Dumping (attack-pattern)
  • DCSync (attack-pattern)
  • InstallUtil (attack-pattern)

Related threat objects

Reports & references

  • cloud.google.com — Updated Cyber Threat Actor Naming System (report)
  • pwc.co.uk — Pwc Cyber Threats 2020 A Year In Retrospect (report)
  • bsi.bund.de — Aktive Apt Gruppen Node (report)
  • CrowdStrike — Report2020Crowdstrikeglobalthreatreport (report)
  • services.google.com — Google Fog Of War Research Report (report)
  • cfr.org — Mustang Panda (report)
  • CrowdStrike — Meet Crowdstrikes Adversary Of The Month For June Mustang Panda (report)
  • secureworks.com — Bronze President (report)
  • darkreading.com — Chinese Apt Bronze President Spy Campaign Russian Military (report)
  • pwc.co.uk — Cyber Threats 2019 Retrospect (report)
  • Trend Micro — Earth Preta Spear Phishing Governments Worldwide (report)
  • proofpoint.com — Ta416 Goes Ground And Returns Golang Plugx Malware Loader (report)
  • proofpoint.com — Good Bad And Web Bug Ta416 Increases Operational Tempo Against European (report)
  • Palo Alto Unit 42 — Stately Taurus Targets Philippines Government Cyberespionage (report)
  • Microsoft — Rw1Afyw (report)
  • jsac.jpcert.or.jp — Jsac2023 2 Lt4 (report)
  • thecyberwire.com — Notes (report)
  • research.checkpoint.com — The Dragon Who Sold His Camaro Analyzing Custom Router Implant (report)
  • cloud.google.com — Prc Nexus Espionage Targets Diplomats (report)
  • raw.githubusercontent.com — Microsoftmapping (report)
  • Microsoft — Microsoft Threat Actor Naming (report)
  • blog.cloudflare.com — 2026 Threat Report (report)
  • MITRE ATT&CK — G0129 (report)
  • blog.eclecticiq.com — Mustang Panda Apt Group Uses European Commission Themed Lure To Deliver Plugx Malware (report)
  • Cisco Talos — Mustang Panda Targets Europe (report)

Attributed from

  • RedDelta Modified PlugX Infection Chain Operations (campaign)
  • RedDelta Updated PlugX Infection Chain (Deprecated) (campaign)

External references