Threat group.View on attack.mitre.org
Mustang Panda is a China-based cyber espionage threat actor that has been conducting operations since at least 2012. Mustang Panda has been known to use tailored phishing lures and decoy documents to deliver malicious payloads. Mustang Panda has targeted government, diplomatic, and non-governmental organizations, including think tanks, religious institutions, and research entities, across the United States, Europe, and Asia, with notable activity in Russia, Mongolia, Myanmar, Pakistan, and Vietnam.
| Technique | Procedure example |
|---|---|
| T1001.003 Protocol or Service Impersonation |
Mustang Panda has utilized TLS record headers in network packets to impersonate various versions of TLS protocols to blend in with legitimate network traffic. Mustang Panda has used FakeTLS to communicate with its C2 servers. |
| T1003 OS Credential Dumping |
Mustang Panda utilized “Hdump” to dump credentials from memory. |
| T1003.001 LSASS Memory |
Mustang Panda has harvested credentials from memory of lssas.exe with Mimikatz. |
| T1003.003 NTDS |
Mustang Panda has used vssadmin to create a volume shadow copy and retrieve the NTDS.dit file. Mustang Panda has also used |
| T1003.006 DCSync |
Mustang Panda has leveraged Mimikatz DCSync feature to obtain user credentials. |
| T1016 System Network Configuration Discovery |
Mustang Panda has used |
| T1018 Remote System Discovery |
Mustang Panda has queried Active Directory for computers using AdFind. Mustang Panda has also utilized SharpNBTScan to scan the victim environment. |
| T1027 Obfuscated Files or Information |
Mustang Panda has delivered initial payloads hidden using archives and encoding measures. Mustang Panda has also utilized opaque predicates in payloads to hinder analysis. 2022 November_TrendMicro_Earth Preta_Toneshell_PubloadAnomali MUSTANG PANDA October 2019Cisco Talos MUSTANG PANDA PLUGX PUBLOAD MAY 2022Crowdstrike MUSTANG PANDA June 2018Eset PlugX Korplug Mustang Panda March 2022Proofpoint TA416 Europe March 2022Proofpoint TA416 November 2020Recorded Future REDDELTA July 2020Secureworks BRONZE PRESIDENT December 2019Sophos PlugX September 2022Unit42 Bookworm Nov2015ZscalerZscaler PAKLOG CorkLog SplatCloak Splatdropper April 2025 |
| T1027.007 Dynamic API Resolution |
Mustang Panda has leveraged obfuscated Windows API function calls that were concealed as unique names, or hashes of the Windows API. |
| T1027.012 LNK Icon Smuggling |
Mustang Panda has utilized LNK files to hide malicious scripts for execution. Mustang Panda has also leveraged LNK files that were programmed to display a PDF icon to entice the victim to click on the file to execute an office.exe binary. |
| T1027.016 Junk Code Insertion |
Mustang Panda has used junk code within their DLL files to hinder analysis. |
| T1036.005 Match Legitimate Resource Name or Location |
Mustang Panda has used names like `adobeupdate.dat` and `PotPlayerDB.dat` to disguise PlugX, and a file named `OneDrive.exe` to load a Cobalt Strike payload. Mustang Panda has also masqueraded legitimate browser plugin updates to include AdobePlugins.exe. |
| T1036.007 Double File Extension |
Mustang Panda has used an additional filename extension to hide the true file type. |
| T1036.008 Masquerade File Type |
Mustang Panda has masqueraded malicious executables as legitimate files that download PlugX malware. |
| T1041 Exfiltration Over C2 Channel |
Mustang Panda has exfiltrated stolen data and files to its C2 server. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.