Mustang Panda is a China-aligned cyber espionage threat actor known for sustained intelligence-collection operations against government, diplomatic, defense, telecommunications, education, energy, and other strategically relevant sectors, particularly across Asia and increasingly in Europe. Widely used aliases include Earth Preta, Camaro Dragon, RedDelta, TA416, Bronze President, Hive0154, Stately Taurus, Twill Typhoon, Tantalum, TEMP.Hex, and LuminousMoth, though some aliases may reflect overlapping reporting clusters or partially distinct subclusters rather than a perfectly uniform actor definition. The group is best known for spearphishing, archive-based delivery, removable-media infection, DLL sideloading, multi-stage loaders, and long-running use of PlugX-family tooling, including SOGU and Korplug variants. Reported campaigns have targeted Indian government entities and hydropower organizations, European government bodies including Serbian aviation-related institutions, and earlier victims in countries such as Vietnam and Australia. Operations are consistent with state-directed espionage priorities, including collection on regional geopolitics, defense relationships, and critical infrastructure planning. Mustang Panda frequently abuses legitimate software and trusted services to reduce detection. Recent activity has used signed executables as sideloading hosts, cloud platforms for command and control and exfiltration, and legitimate storage or collaboration services to blend malicious traffic with normal enterprise activity. Documented tooling associated with the actor includes SHARDLOADER, MINIRECON, ZOHOMURK, TONESHELL-derived implants, LotusLite, Yokai-linked activity under the broader Hive0154 umbrella, and multiple PlugX infection chains. In some campaigns, the actor used Zoho WorkDrive as a covert command-and-control and data exfiltration channel; in others, it used WebSocket-over-HTTPS, proxy-aware communications, or staged shellcode loaders that manually map payloads in memory. Tradecraft commonly includes hidden or obfuscated DLLs, shellcode reconstruction and decryption, API hashing, PEB walking, anti-analysis timing checks, single-instance guards, scheduled-task or Run-key persistence, system information discovery, proxy discovery, and interactive post-compromise reconnaissance. The actor has repeatedly used decoy documents and politically themed lures, often packaged in compressed archives containing shortcut files or sideloading components. Some campaigns also demonstrate interest in air-gapped or segmented environments through USB-borne propagation or supply-chain compromise involving removable media. Behaviorally, Mustang Panda overlaps substantially with other Chinese intrusion sets in discovery, credential access, defense evasion, and modular tool reuse. Public reporting consistently places the actor within the broader ecosystem of Chinese state-linked espionage operations, with emphasis on stealthy persistence, adaptable loader chains, and reuse of evolving malware families across regional intelligence targets.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Geographies tied to known operations.
59 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
42 malware families attributed to this actor across reporting.
37 additional families tracked in Mallory.
6 CVEs this actor has used in observed campaigns. 6 of them exploited in the wild.
Microsoft has been aware of the flaw, tracked as CVE-2025-9491, at least since September 2024, when the Zero Day Initiative identified it as ZDI-25-148 and ZDI-CAN-25373 and notified Redmond. The vulnerability exists in how Windows processes .lnk files, which are desktop icons acting as a shortcut to another file or application.
...used exploits for... Word (CVE-2017-0199)...
Details on Exploited Vulnerabilities ... CVE-2021-1675 Microsoft Windows ... YARA Rules ... reference = “... PrintNightmare and MSHTML exploits” ... $cve1 = “CVE-2021-1675”
Details on Exploited Vulnerabilities ... CVE-2021-40444 Microsoft Windows ... YARA Rules ... reference = “... PrintNightmare and MSHTML exploits” ... $cve2 = “CVE-2021-40444”
Three Attack Variants Observed GrimResource (CVE-2025-26633): XSS via apds.dll res:// protocol handler
1 more CVE tied to this actor tracked in Mallory.
729 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Used multiple malware families and abused Zoho WorkDrive for command-and-control and data exfiltration.
Associated with a backdoor sample codenamed “SolidPDFCreator” used in a campaign labeled “Target India – Campaign 3.”
Operates the SolidPDFCreator DLL backdoor using DLL side-loading, persistence via a scheduled task named MediumNetMonIt, and execution of decrypted shellcode from RWX memory, with the shellcode likely delivering a follow-on payload such as Cobalt Strike.
Linked to malware found on counterfeit USB drives supplied to Japan’s Ground Self-Defense Force, in a supply-chain style compromise affecting secure military networks. The group is also described as previously targeting government, education, and telecommunications sectors.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.