Mustang Panda
G0129APT / State-SponsoredChinaActive
Also known as: TA416 · RedDelta · BRONZE PRESIDENT · STATELY TAURUS · FIREANT · CAMARO DRAGON · EARTH PRETA · HIVE0154 · TWILL TYPHOON · TANTALUM · LUMINOUS MOTH · UNC6384 · TEMP.Hex · Red Lich · ClumsyToad
Overview
Mustang Panda is a China-based cyber espionage threat actor that has been conducting operations since at least 2012. Mustang Panda has been known to use tailored phishing lures and decoy documents to deliver malicious payloads. Mustang Panda has targeted government, diplomatic, and non-governmental organizations, including think tanks, religious institutions, and research entities, across the United States, Europe, and Asia, with notable activity in Russia, Mongolia, Myanmar, Pakistan, and Vietnam.
Campaigns — 1
RedDelta Modified PlugX Infection Chain Operations
ended2023-07 → 2024-12
Source: MITRE C0047
T1016System Network Configuration DiscoveryDiscovery
T1608.001Upload MalwareResource Development
T1583.006Web ServicesResource Development
T1047Windows Management InstrumentationExecution
T1573.001Symmetric CryptographyCommand and Control
T1593Search Open Websites/DomainsReconnaissance
T1204.001Malicious LinkExecution
T1046Network Service DiscoveryDiscovery
Malware & Tools — 23
CANONSTAGERMalwareWindows
STATICPLUGINMalwareWindows
ShadowPadMalwareWindows
TONESHELLMalwareWindows
Cobalt StrikeMalwareLinux / macOS / Windows
HIUPANMalwareWindows
ImpacketToolLinux / macOS / Windows
SplatCloakMalwareWindows
PAKLOGMalwareWindows
Wevtutil
T1140
Deobfuscate/Decode Files or Information
Stealth
T1049System Network Connections DiscoveryDiscovery
T1059.005Visual BasicExecution
T1219.001IDE TunnelingCommand and Control
T1567.002Exfiltration to Cloud StorageExfiltration
T1053.005Scheduled TaskExecution
T1087.002Domain AccountDiscovery
T1598.003Spearphishing LinkReconnaissance
T1678Delay ExecutionStealth
T1564.001Hidden Files and DirectoriesStealth
T1027.007Dynamic API ResolutionStealth
T1585.002Email AccountsResource Development
T1219.002Remote Desktop SoftwareCommand and Control
T1218.004InstallUtilStealth
T1586.002Email AccountsResource Development
T1560.001Archive via UtilityCollection
T1070Indicator RemovalStealth
T1071.001Web ProtocolsCommand and Control
T1018Remote System DiscoveryDiscovery
T1069.002Domain GroupsDiscovery
T1001.003Protocol or Service ImpersonationCommand and Control
T1048.003Exfiltration Over Unencrypted Non-C2 ProtocolExfiltration
T1566.002Spearphishing LinkInitial Access
T1041Exfiltration Over C2 ChannelExfiltration
T1072Software Deployment ToolsExecution
T1557Adversary-in-the-MiddleCredential Access
T1505.003Web ShellPersistence
T1176.002IDE ExtensionsPersistence
T1588.003Code Signing CertificatesResource Development
T1091Replication Through Removable MediaLateral Movement
T1059.003Windows Command ShellExecution
T1052.001Exfiltration over USBExfiltration
T1003.001LSASS MemoryCredential Access
T1588.002ToolResource Development
T1588.004Digital CertificatesResource Development
T1560.003Archive via Custom MethodCollection
T1070.004File DeletionStealth
T1129Shared ModulesExecution
T1057Process DiscoveryDiscovery
T1082System Information DiscoveryDiscovery
T1095Non-Application Layer ProtocolCommand and Control
Tool
Windows
CLAIMLOADERMalwareWindows
NBTscanToolWindows / Linux / macOS
SplatDropperMalwareWindows
China ChopperMalwareWindows