🔴 [LATEST] 313 TEAM TARGETS AL RAJHI BANK AND SAUDI CIVIL DEFENSE, SITES UNREACHABLE FROM DOZENS OF LOCATIONS    ◆    🔴 [LATEST] DDOS QATAR INVESTMENT AUTHORITY: 1 CRITICAL SOVEREIGN WEB PORTAL DOWN    ◆    🔴 [LATEST] RIPPERSEC TARGETS ISRAEL CART: 1 CRITICAL E-COMMERCE PLATFORM DISRUPTED    ◆    🔴 [LATEST] US NAVY DDOS ATTACK: 3 CRITICAL MILITARY PORTALS DISRUPTED    ◆    🔴 [LATEST] QATAR LIVING DDOS ATTACK: 1 CRITICAL EXPATRIATE PORTAL DISRUPTED

> CLASSIFIED_DOSSIER :: THREAT_ACTOR_PROFILE

Flag
MUSTANG PANDA

/actor/mustang-panda/  ·  0 intel reports

Year Established
2012
Attribution
China (MSS)
Motivation
Espionage, Political Intelligence
Modus Operandi (MO)
Spear-phishing with PlugX malware, USB propagation, targeting Southeast Asian governments and NGOs
Primary Aliases
Bronze President, TA416, HoneyMyte, Red Delta, Earth Preta, BASIN

Mustang Panda is a prolific Chinese state-sponsored threat actor attributed to the Ministry of State Security (MSS) with a primary focus on cyber espionage targeting governments, NGOs, research institutions, and religious organisations in Southeast Asia, Europe, and the United States. The group is particularly known for targeting entities whose work relates to Chinese foreign policy priorities.

Mustang Panda's signature tool is PlugX (also known as Korplug). The group delivers PlugX primarily through spear-phishing campaigns featuring politically relevant lure documents themed around regional affairs, border tensions, or international relations topics likely to be of interest to the targeted individuals or organisations.

A distinctive operational capability demonstrated by Mustang Panda is their use of USB propagation. This technique is particularly relevant when targeting government agencies in developing nations where physical document sharing via USB remains common despite network security controls.

Mustang Panda has demonstrated particular targeting intensity against Myanmar, the Philippines, Mongolia, Vietnam, and European entities engaged in refugee affairs and diplomatic activities. European NGOs working with Uyghur communities have been repeatedly targeted in what appears to be a coordinated effort to monitor and suppress international advocacy for Chinese minority groups.

STATUS: ACTIVE CLASSIFICATION: STATE-SPONSORED (APT) LAST SEEN: Unknown

> LINKED_INTEL_REPORTS (0)

[NULL] No intel reports found for this actor.

> cd ../articles