Mustang Panda is a China-linked cyber-espionage threat actor known for sustained operations against government entities and other organizations across Asia and beyond. Widely used aliases include HoneyMyte, Bronze President, RedDelta, TA416, Camaro Dragon, Earth Preta, Twill Typhoon, LuminousMoth, Stately Taurus, Tantalum, Cobalt Shadow, Fireant, Temp.Hex, and UNC6384. Reporting also distinguishes some activity clusters such as RedDelta and LuminousMoth as closely associated naming conventions within the broader tracking landscape. The actor is best known for espionage-focused intrusions using malware families such as PlugX and CoolClient, and has also been associated with use of Cobalt Strike and a Go-based loader. Recent CoolClient activity shows a mature multi-stage infection chain using DLL sideloading with renamed legitimate software, staged loaders, encrypted configuration data, scheduled-task and service-based persistence, process injection, and privilege escalation via an RPC-based UAC bypass combined with parent-process spoofing. In newer operations, CoolClient has evolved beyond a user-mode backdoor through deployment of a signed kernel-mode driver that provides rootkit functionality, including hiding processes, files, registry artifacts, kernel modules, and selected network information from user-mode tools. Observed and documented capabilities also include keylogging, clipboard theft, credential harvesting, file management, plugin support, and HTTP traffic interception. Mustang Panda routinely uses Windows-native and dual-use tooling for host and network reconnaissance and operational execution. Documented tradecraft includes PowerShell-based execution, mshta-launched HTA content, batch-script collection, scheduled tasks for persistence, AutoRun and Run-key persistence, downloading additional payloads after initial compromise, process discovery with tasklist, system discovery with systeminfo, network discovery with ipconfig and arp, and Active Directory enumeration with AdFind. The group has also used hidden folders and hidden or system file attributes on removable media to conceal malware and collected data, and has repeatedly abused legitimate signed executables for DLL sideloading and masquerading. Targeting has heavily focused on Asia, with documented victims in Pakistan, Mongolia, and Myanmar, and broader activity affecting Russia and other regional states. Confirmed targeting includes government entities, and the actor is consistently characterized as an espionage operator rather than a financially motivated intrusion set.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
59 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
38 malware families attributed to this actor across reporting.
33 additional families tracked in Mallory.
6 CVEs this actor has used in observed campaigns. 6 of them exploited in the wild.
Microsoft has been aware of the flaw, tracked as CVE-2025-9491, at least since September 2024, when the Zero Day Initiative identified it as ZDI-25-148 and ZDI-CAN-25373 and notified Redmond. The vulnerability exists in how Windows processes .lnk files, which are desktop icons acting as a shortcut to another file or application.
...used exploits for... Word (CVE-2017-0199)...
Details on Exploited Vulnerabilities ... CVE-2021-1675 Microsoft Windows ... YARA Rules ... reference = “... PrintNightmare and MSHTML exploits” ... $cve1 = “CVE-2021-1675”
Details on Exploited Vulnerabilities ... CVE-2021-40444 Microsoft Windows ... YARA Rules ... reference = “... PrintNightmare and MSHTML exploits” ... $cve2 = “CVE-2021-40444”
Three Attack Variants Observed GrimResource (CVE-2025-26633): XSS via apds.dll res:// protocol handler
1 more CVE tied to this actor tracked in Mallory.
1,130 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Espionage intrusions deploying PlugX for initial foothold and CoolClient as a secondary backdoor, now enhanced with a signed kernel-mode rootkit/driver to hide processes, files, registry entries, and network activity.
Cyber-espionage operations involving an evolved CoolClient backdoor, with recent intrusions observed in late 2025 and 2026 targeting organizations in Asia and Russia, including campaigns against Pakistan, Mongolia, and Myanmar. In the Myanmar campaign, PlugX was used as an initial implant before deployment of CoolClient.
Conducting targeted espionage intrusions using the CoolClient backdoor, including a newer multi-stage Windows infection chain that abuses DLL sideloading and can deploy a signed kernel driver (msagent.sys) to hide or protect malware files, registry keys, and processes.
Cyber-espionage activity using PlugX as an initial post-compromise implant and CoolClient as a secondary backdoor; the latest observed variant adds a signed Windows kernel-mode rootkit driver for stealth, persistence, process/file/registry protection, and network data filtering.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.