Skip to main content
QUIETLYTIC
Threat Actor

Mustang Panda

China-based cyber espionage actor, per MITRE ATT&CK, conducting operations since at least 2012 using tailored phishing lures against government, diplomatic, and NGO targets.

Threat Level
HIGH
Attribution
China-based, per MITRE ATT&CK's group profile
Also Known As
TA416, RedDelta, BRONZE PRESIDENT, STATELY TAURUS, FIREANT, CAMARO DRAGON, EARTH PRETA, HIVE0154, TWILL TYPHOON, TANTALUM, LUMINOUS MOTH, UNC6384, TEMP.Hex, Red Lich, ClumsyToad
Targets
Government, diplomatic, and non-governmental organizations, Think tanks and religious institutions, United States, Europe, and Asia (notably Russia, Mongolia, Myanmar, Pakistan, Vietnam)

Overview

Mustang Panda (MITRE ATT&CK ID G0129) is a China-based cyber espionage threat actor MITRE ATT&CK documents as conducting operations since at least 2012. Per MITRE’s profile, Mustang Panda is known for tailored phishing lures and decoy documents to deliver malicious payloads, targeting government, diplomatic, and non-governmental organizations — including think tanks, religious institutions, and research entities — across the United States, Europe, and Asia, with notable activity in Russia, Mongolia, Myanmar, Pakistan, and Vietnam. MITRE’s documentation cites reporting including a December 2024 US Department of Justice affidavit describing a court-authorized operation against Mustang Panda’s PlugX infrastructure.

Known tools and malware (per MITRE ATT&CK relationship data)

Our ingested data links Mustang Panda to an extensive PlugX-centered toolset: PlugX itself, plus TONESHELL, ShadowPad, RCSession, StarProxy, PUBLOAD, CLAIMLOADER, CANONSTAGER, STATICPLUGIN, HIUPAN, CorKLOG, BOOKWORM, PoisonIvy, and China Chopper, alongside Cobalt Strike, Mimikatz, and Impacket.

Notable techniques (per MITRE ATT&CK relationship data)

Techniques linked to Mustang Panda in our data include Adversary-in-the-Middle (T1557), Archive via Custom Method (T1560.003) and Archive via Utility (T1560.001), Automated Collection (T1119), Code Signing (T1553.002) and Code Signing Certificates (T1588.003), and DCSync (T1003.006).

Per MITRE ATT&CK’s relationship data, Mustang Panda is linked to “RedDelta Modified PlugX Infection Chain Operations,” a campaign named directly for the group’s characteristic malware family.

What we don’t have

MITRE’s ingested data doesn’t include a first-seen/last-seen activity date range for groups — we report “active since at least 2012” per MITRE’s description text. We have no independent telemetry or IOC data beyond MITRE’s STIX bundle.

Frequently Asked Questions

What is Mustang Panda? A China-based cyber espionage actor, per MITRE ATT&CK, active since at least 2012, known for phishing-delivered PlugX malware against government, diplomatic, and NGO targets.

How many aliases does Mustang Panda have? MITRE ATT&CK tracks 15 aliases for this group, including RedDelta, BRONZE PRESIDENT, and TWILL TYPHOON — reflecting years of independent vendor tracking before cluster overlap was recognized.

What malware is Mustang Panda linked to? Per MITRE ATT&CK’s relationship data: PlugX, TONESHELL, ShadowPad, RCSession, and PoisonIvy, among others.


Data sourced from MITRE ATT&CK® (https://attack.mitre.org), group ID G0129, aggregated September 7, 2026. This product uses MITRE ATT&CK data but is not endorsed or certified by MITRE. See more threat actor profiles.

Report an error

Found a factual error, an outdated figure, or a broken source link? Let us know and our editorial desk will review it.


Related intelligence


Cross-referenced intelligence


Analyst tools