{"id":436,"count":0,"description":"<div class=\"actor-dossier\" style=\"display:flex;flex-wrap:wrap;gap:12px;margin-bottom:20px\">\n  <div style=\"flex:1;min-width:160px;background:#0d1117;border:1px solid #30363d;border-radius:8px;padding:12px\">\n    <span style=\"color:#8b949e;font-size:11px;text-transform:uppercase;letter-spacing:1px\">Year Established<\/span>\n    <div style=\"color:#e6edf3;font-weight:600;margin-top:4px\">2012<\/div>\n  <\/div>\n  <div style=\"flex:1;min-width:160px;background:#0d1117;border:1px solid #30363d;border-radius:8px;padding:12px\">\n    <span style=\"color:#8b949e;font-size:11px;text-transform:uppercase;letter-spacing:1px\">Attribution<\/span>\n    <div style=\"color:#e6edf3;font-weight:600;margin-top:4px\">China (MSS)<\/div>\n  <\/div>\n  <div style=\"flex:1;min-width:160px;background:#0d1117;border:1px solid #30363d;border-radius:8px;padding:12px\">\n    <span style=\"color:#8b949e;font-size:11px;text-transform:uppercase;letter-spacing:1px\">Motivation<\/span>\n    <div style=\"color:#e6edf3;font-weight:600;margin-top:4px\">Espionage, Political Intelligence<\/div>\n  <\/div>\n  <div style=\"flex:2;min-width:200px;background:#0d1117;border:1px solid #30363d;border-radius:8px;padding:12px\">\n    <span style=\"color:#8b949e;font-size:11px;text-transform:uppercase;letter-spacing:1px\">Modus Operandi (MO)<\/span>\n    <div style=\"color:#e6edf3;font-weight:600;margin-top:4px\">Spear-phishing with PlugX malware, USB propagation, targeting Southeast Asian governments and NGOs<\/div>\n  <\/div>\n  <div style=\"flex:2;min-width:200px;background:#0d1117;border:1px solid #30363d;border-radius:8px;padding:12px\">\n    <span style=\"color:#8b949e;font-size:11px;text-transform:uppercase;letter-spacing:1px\">Primary Aliases<\/span>\n    <div style=\"color:#e6edf3;font-weight:600;margin-top:4px\">Bronze President, TA416, HoneyMyte, Red Delta, Earth Preta, BASIN<\/div>\n  <\/div>\n<\/div>\n<p>Mustang Panda is a prolific Chinese state-sponsored threat actor attributed to the Ministry of State Security (MSS) with a primary focus on cyber espionage targeting governments, NGOs, research institutions, and religious organisations in Southeast Asia, Europe, and the United States. The group is particularly known for targeting entities whose work relates to Chinese foreign policy priorities \u2014 including organisations focused on Tibetan, Uyghur, and Taiwanese affairs, as well as government ministries in nations that share borders or strategic competition with China.<\/p>\n<p>Mustang Panda's signature tool is PlugX (also known as Korplug) \u2014 a remote access trojan that has been used by multiple Chinese APT groups but remains most closely associated with Mustang Panda due to their distinctive custom variants. The group delivers PlugX primarily through spear-phishing campaigns featuring politically relevant lure documents themed around regional affairs, border tensions, or international relations topics likely to be of interest to the targeted individuals or organisations.<\/p>\n<p>A distinctive operational capability demonstrated by Mustang Panda is their use of USB propagation \u2014 malware that spreads through connected USB drives to enable compromise of air-gapped or isolated systems that cannot be reached through network-based attacks. This technique is particularly relevant when targeting government agencies in developing nations where physical document sharing via USB remains common despite network security controls.<\/p>\n<p>Mustang Panda has demonstrated particular targeting intensity against Myanmar, the Philippines, Mongolia, Vietnam, and European entities engaged in refugee affairs and diplomatic activities \u2014 reflecting Chinese strategic intelligence priorities regarding the Indo-Pacific region and China's relationships with neighbouring states. European NGOs working with Uyghur communities have been repeatedly targeted in what appears to be a coordinated effort to monitor and suppress international advocacy for Chinese minority groups.<\/p>","link":"https:\/\/cyberasia.io\/actor\/mustang-panda\/","name":"Mustang Panda","slug":"mustang-panda","taxonomy":"threat_actor","parent":0,"meta":[],"_links":{"self":[{"href":"https:\/\/cyberasia.io\/people\/wp-json\/wp\/v2\/threat_actors\/436","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/cyberasia.io\/people\/wp-json\/wp\/v2\/threat_actors"}],"about":[{"href":"https:\/\/cyberasia.io\/people\/wp-json\/wp\/v2\/taxonomies\/threat_actor"}],"wp:post_type":[{"href":"https:\/\/cyberasia.io\/people\/wp-json\/wp\/v2\/posts?threat_actors=436"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}