ATT&CKGroupsMustang Panda

Mustang Panda

G0129

Threat group.View on attack.mitre.org

About this group

Mustang Panda is a China-based cyber espionage threat actor that has been conducting operations since at least 2012. Mustang Panda has been known to use tailored phishing lures and decoy documents to deliver malicious payloads. Mustang Panda has targeted government, diplomatic, and non-governmental organizations, including think tanks, religious institutions, and research entities, across the United States, Europe, and Asia, with notable activity in Russia, Mongolia, Myanmar, Pakistan, and Vietnam.

Techniques used85

Procedure examples85

TechniqueProcedure example
T1001.003
Protocol or Service Impersonation

Mustang Panda has utilized TLS record headers in network packets to impersonate various versions of TLS protocols to blend in with legitimate network traffic. Mustang Panda has used FakeTLS to communicate with its C2 servers.

T1003
OS Credential Dumping

Mustang Panda utilized “Hdump” to dump credentials from memory.

T1003.001
LSASS Memory

Mustang Panda has harvested credentials from memory of lssas.exe with Mimikatz.

T1003.003
NTDS

Mustang Panda has used vssadmin to create a volume shadow copy and retrieve the NTDS.dit file. Mustang Panda has also used reg save on the SYSTEM file Registry location to help extract the NTDS.dit file.

T1003.006
DCSync

Mustang Panda has leveraged Mimikatz DCSync feature to obtain user credentials.

T1016
System Network Configuration Discovery

Mustang Panda has used ipconfig and arp to determine network configuration information. Mustang Panda has also utilized SharpNBTScan to scan the victim environment.

T1018
Remote System Discovery

Mustang Panda has queried Active Directory for computers using AdFind. Mustang Panda has also utilized SharpNBTScan to scan the victim environment.

T1027
Obfuscated Files or Information

Mustang Panda has delivered initial payloads hidden using archives and encoding measures. Mustang Panda has also utilized opaque predicates in payloads to hinder analysis.

T1027.007
Dynamic API Resolution

Mustang Panda has leveraged obfuscated Windows API function calls that were concealed as unique names, or hashes of the Windows API.

T1027.012
LNK Icon Smuggling

Mustang Panda has utilized LNK files to hide malicious scripts for execution. Mustang Panda has also leveraged LNK files that were programmed to display a PDF icon to entice the victim to click on the file to execute an office.exe binary.

T1027.016
Junk Code Insertion

Mustang Panda has used junk code within their DLL files to hinder analysis.

T1036.005
Match Legitimate Resource Name or Location

Mustang Panda has used names like `adobeupdate.dat` and `PotPlayerDB.dat` to disguise PlugX, and a file named `OneDrive.exe` to load a Cobalt Strike payload. Mustang Panda has also masqueraded legitimate browser plugin updates to include AdobePlugins.exe.

T1036.007
Double File Extension

Mustang Panda has used an additional filename extension to hide the true file type.

T1036.008
Masquerade File Type

Mustang Panda has masqueraded malicious executables as legitimate files that download PlugX malware.

T1041
Exfiltration Over C2 Channel

Mustang Panda has exfiltrated stolen data and files to its C2 server.

View all 85 procedure examples

Software23

Campaigns1

References13

  1. ATTACKIQ MUSTANG PANDA TONESHELL March 2023 Open source
    Ken Towne, Francis Guibernau. (2023, March 23). Emulating the Politically Motivated Chinese APT Mustang Panda. Retrieved September 10, 2025.
  2. Anomali MUSTANG PANDA October 2019 Open source
    Anomali Threat Research. (2019, October 7). China-Based APT Mustang Panda Targets Minority Groups, Public and Private Sector Organizations. Retrieved April 12, 2021.
  3. BlackBerry MUSTANG PANDA October 2022 Open source
    The BlackBerry Research and Intelligence Team. (2022, October 6). Mustang Panda Abuses Legitimate Apps to Target Myanmar Based Victims. Retrieved October 14, 2025.
  4. Cisco Talos MUSTANG PANDA PLUGX PUBLOAD MAY 2022 Open source
    Asheer Malhotra, Jungsoo An, Kendall Mc. (2022, May 5). Mustang Panda deploys a new wave of malware targeting Europe. Retrieved August 4, 2025.
  5. Crowdstrike MUSTANG PANDA June 2018 Open source
    Meyers, A. (2018, June 15). Meet CrowdStrike’s Adversary of the Month for June: MUSTANG PANDA. Retrieved April 12, 2021.
  6. DOJ Affidavit Search and Seizure PlugX December 2024 Open source
    DOJ. (2024, December 20). Mag. No. 24-mj-1387 AFFIDAVIT IN SUPPORT OF AN APPLICATION FOR A NINTH SEARCH AND SEIZURE WARRANT- IN THE MATTER OF THE SEARCH AND SEIZURE OF COMPUTERS IN THE UNITED STATES INFECTED WITH PLUGX MALWARE . Retrieved September 9, 2025.
  7. EclecticIQ Mustang Panda PlugX Open source
    EclecticIQ Threat Research Team. (2023, February 2). Mustang Panda APT Group Uses European Commission-Themed Lure to Deliver PlugX Malware. Retrieved September 9, 2025.
  8. Eset PlugX Korplug Mustang Panda March 2022 Open source
    Alexandre Cote Cyr. (2022, March 23). Mustang Panda’s Hodur: Old tricks, new Korplug variant. Retrieved September 9, 2025.
  9. Palo Alto Networks, Unit 42 Open source
    Robert Falcone. (2025, February 20). Stately Taurus Activity in Southeast Asia Links to Bookworm Malware. Retrieved July 21, 2025.
  10. Secureworks BRONZE PRESIDENT December 2019 Open source
    Counter Threat Unit Research Team. (2019, December 29). BRONZE PRESIDENT Targets NGOs. Retrieved April 13, 2021.
  11. Sophos Mustang Panda PLUGX Open source
    Secureworks Counter Threat Unit Research Team. (2022, September 8). BRONZE PRESIDENT Targets Government Officials. Retrieved September 9, 2025.
  12. Sophos PlugX September 2022 Open source
    Secureworks Counter Threat Unit Research Team. (2022, April 27). BRONZE PRESIDENT Targets Russian Speakers with Updated PlugX. Retrieved September 9, 2025.
  13. Zscaler Open source
    Sudeep Singh. (2025, April 16). Latest Mustang Panda Arsenal: ToneShell and StarProxy | P1. Retrieved July 21, 2025.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.