Overview
Mustang Panda (MITRE ATT&CK ID G0129) is a China-based cyber espionage threat actor MITRE ATT&CK documents as conducting operations since at least 2012. Per MITRE’s profile, Mustang Panda is known for tailored phishing lures and decoy documents to deliver malicious payloads, targeting government, diplomatic, and non-governmental organizations — including think tanks, religious institutions, and research entities — across the United States, Europe, and Asia, with notable activity in Russia, Mongolia, Myanmar, Pakistan, and Vietnam. MITRE’s documentation cites reporting including a December 2024 US Department of Justice affidavit describing a court-authorized operation against Mustang Panda’s PlugX infrastructure.
Known tools and malware (per MITRE ATT&CK relationship data)
Our ingested data links Mustang Panda to an extensive PlugX-centered toolset: PlugX itself, plus TONESHELL, ShadowPad, RCSession, StarProxy, PUBLOAD, CLAIMLOADER, CANONSTAGER, STATICPLUGIN, HIUPAN, CorKLOG, BOOKWORM, PoisonIvy, and China Chopper, alongside Cobalt Strike, Mimikatz, and Impacket.
Notable techniques (per MITRE ATT&CK relationship data)
Techniques linked to Mustang Panda in our data include Adversary-in-the-Middle (T1557), Archive via Custom Method (T1560.003) and Archive via Utility (T1560.001), Automated Collection (T1119), Code Signing (T1553.002) and Code Signing Certificates (T1588.003), and DCSync (T1003.006).
Related campaigns
Per MITRE ATT&CK’s relationship data, Mustang Panda is linked to “RedDelta Modified PlugX Infection Chain Operations,” a campaign named directly for the group’s characteristic malware family.
What we don’t have
MITRE’s ingested data doesn’t include a first-seen/last-seen activity date range for groups — we report “active since at least 2012” per MITRE’s description text. We have no independent telemetry or IOC data beyond MITRE’s STIX bundle.
Frequently Asked Questions
What is Mustang Panda? A China-based cyber espionage actor, per MITRE ATT&CK, active since at least 2012, known for phishing-delivered PlugX malware against government, diplomatic, and NGO targets.
How many aliases does Mustang Panda have? MITRE ATT&CK tracks 15 aliases for this group, including RedDelta, BRONZE PRESIDENT, and TWILL TYPHOON — reflecting years of independent vendor tracking before cluster overlap was recognized.
What malware is Mustang Panda linked to? Per MITRE ATT&CK’s relationship data: PlugX, TONESHELL, ShadowPad, RCSession, and PoisonIvy, among others.
Data sourced from MITRE ATT&CK® (https://attack.mitre.org), group ID G0129, aggregated September 7, 2026. This product uses MITRE ATT&CK data but is not endorsed or certified by MITRE. See more threat actor profiles.