Mustang Panda, also known as HoneyMyte, is a China-linked cyberespionage threat actor primarily targeting government organizations in Asia and Europe. Recent activity has targeted government and private-sector organizations in Myanmar, Mongolia, Pakistan, Russia, and India. The group has used PlugX as an initial post-compromise implant and deployed the CoolClient modular backdoor for system reconnaissance, keylogging, clipboard collection, credential harvesting, file operations, and command-and-control. In campaigns observed in late 2025 and 2026, Mustang Panda deployed an evolved CoolClient variant using a signed kernel-mode driver that provides rootkit-like stealth and protection. The malware chain used DLL sideloading through a renamed legitimate application, Microsoft Defender exclusion abuse, scheduled-task execution at SYSTEM privileges, process injection, registry-based persistence, and Windows services. The kernel component can conceal and protect malware processes, files, registry objects, and command-and-control network artifacts, including through filtering of network information returned to user-mode tools. Its available functionality also includes kernel-module hiding, shellcode injection, removal of process-protection controls, and arbitrary kernel-memory modification. Mustang Panda has also used curl to exfiltrate archived data to cloud services.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
42 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
32 malware families attributed to this actor across reporting.
27 additional families tracked in Mallory.
6 CVEs this actor has used in observed campaigns. 6 of them exploited in the wild.
Microsoft has been aware of the flaw, tracked as CVE-2025-9491, at least since September 2024, when the Zero Day Initiative identified it as ZDI-25-148 and ZDI-CAN-25373 and notified Redmond. The vulnerability exists in how Windows processes .lnk files, which are desktop icons acting as a shortcut to another file or application.
...used exploits for... Word (CVE-2017-0199)...
Details on Exploited Vulnerabilities ... CVE-2021-1675 Microsoft Windows ... YARA Rules ... reference = “... PrintNightmare and MSHTML exploits” ... $cve1 = “CVE-2021-1675”
Details on Exploited Vulnerabilities ... CVE-2021-40444 Microsoft Windows ... YARA Rules ... reference = “... PrintNightmare and MSHTML exploits” ... $cve2 = “CVE-2021-40444”
Three Attack Variants Observed GrimResource (CVE-2025-26633): XSS via apds.dll res:// protocol handler
1 more CVE tied to this actor tracked in Mallory.
1,159 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Cited as using curl to exfiltrate archives to cloud services.
Mentionné uniquement comme contexte historique d’une opération ayant supprimé PlugX d’ordinateurs américains infectés.
Mentioned only as a comparison to prior U.S. takedown operations.
Mentioned as the group tied to a separate 2025 FBI operation removing PlugX surveillance malware from infected U.S. systems.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.