MUSTANG PANDA
MISPNation-state
CN
Unknown
[Mustang Panda](https://attack.mitre.org/groups/G0129) is a China-based cyber espionage threat actor that has been conducting operations since at least 2012. [Mustang Panda](https://attack.mitre.org/groups/G0129) has been known to use tailored phishing lures and decoy documents to deliver malicious payloads. [Mustang Panda](https://attack.mitre.org/groups/G0129) has targeted government, diplomatic, and non-governmental organizations, including think tanks, religious institutions, and research entities, across the United States, Europe, and Asia, with notable activity in Russia, Mongolia, Myanmar, Pakistan, and Vietnam. (Citation: BlackBerry MUSTANG PANDA October 2022)(Citation: Eset PlugX Korplug Mustang Panda March 2022)(Citation: Anomali MUSTANG PANDA October 2019)(Citation: Cisco Talos MUSTANG PANDA PLUGX PUBLOAD MAY 2022)(Citation: Secureworks BRONZE PRESIDENT December 2019)(Citation: DOJ Affidavit Search and Seizure PlugX December 2024)(Citation: EclecticIQ Mustang Panda PlugX)(Citation: ATTACKIQ MUSTANG PANDA TONESHELL March 2023)(Citation: Crowdstrike MUSTANG PANDA June 2018)(Citation: Palo Alto Networks, Unit 42)(Citation: Sophos PlugX September 2022)(Citation: Sophos Mustang Panda PLUGX)(Citation: Zscaler)
Tecniche Utilizzate (85)
| ID | ATT&CK | Tattiche |
|---|---|---|
| T1001.003 | Protocol or Service Impersonation | - |
| T1003 | OS Credential Dumping | - |
| T1003.001 | LSASS Memory | - |
| T1003.003 | NTDS | - |
| T1003.006 | DCSync | - |
| T1016 | System Network Configuration Discovery | - |
| T1018 | Remote System Discovery | - |
| T1027 | Obfuscated Files or Information | - |
| T1027.007 | Dynamic API Resolution | - |
| T1027.012 | LNK Icon Smuggling | - |
| T1027.016 | Junk Code Insertion | - |
| T1036.005 | Match Legitimate Resource Name or Location | - |
| T1036.007 | Double File Extension | - |
| T1036.008 | Masquerade File Type | - |
| T1041 | Exfiltration Over C2 Channel | - |
Riferimenti (10)
- cfr.org - Mustang Panda
- crowdstrike.com - Meet Crowdstrikes Adversary Of The Month For June Mustang Panda
- go.crowdstrike.com - Report2020CrowdStrikeGlobalThreatReport.pdf
- secureworks.com - Bronze President
- darkreading.com - Chinese Apt Bronze President Spy Campaign Russian Military
- pwc.co.uk - Cyber Threats 2019 Retrospect.pdf
- pwc.co.uk - Pwc Cyber Threats 2020 A Year In Retrospect.pdf
- services.google.com - Google Fog Of War Research Report.pdf
- trendmicro.com - Earth Preta Spear Phishing Governments Worldwide
- proofpoint.com - Ta416 Goes Ground And Returns Golang Plugx Malware Loader
Alias (2692)
Malware Utilizzato (23)
Metadata
| ID: | 176 |
| Created: | 13/01/2026 17:48 |
| Updated: | 06/03/2026 04:00 |