Mustang Panda, also tracked as ITG27 and formerly Hive0154, is a China-aligned state-sponsored espionage threat actor associated with long-running cyber operations that support Chinese regional strategic interests. Public reporting has also linked overlapping activity clusters and aliases including Stately Taurus, Camaro Dragon, Twill Typhoon, Earth Preta, UNK_SteadySplit, and Polaris. The actor has targeted Indian government entities and the energy sector, including activity themed around hydropower cooperation and regional geopolitical issues. Observed intrusion chains relied on spearphishing lures and archive-based delivery, followed by DLL sideloading to launch Claimloader and deploy Toneshell. In documented 2026 activity, the group used a Claimloader variant for persistence and in-memory execution of Toneshell v10, a backdoor that supported interactive command execution, reverse shell functionality, and file transfer over secure WebSocket-based command and control. Live intrusion observations showed sustained hands-on-keyboard tradecraft consistent with espionage objectives. Operators performed reconnaissance, credential harvesting, malware deployment, interactive browsing of victim systems, and theft of documents. A newly identified VNC-capable backdoor, Havencode, was used to provide hidden and active remote desktop access, enabling operators to navigate victim desktops and applications directly. In at least one intrusion, the actor compressed documents and exfiltrated them over SFTP. Working-hour patterns aligned with China Standard Time further supported the China nexus assessment. The actor's operations in the observed cases were focused on intelligence collection rather than disruptive or destructive effects.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
35 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
4 malware families attributed to this actor across reporting.
19 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Espionnage ciblant notamment le gouvernement indien et le secteur énergétique via spearphishing, DLL side-loading, persistence registre, déploiement de Claimloader, Toneshell v10 et Havencode, puis reconnaissance, collecte d’identifiants et exfiltration de documents.
China-aligned cyber espionage campaigns targeting India’s energy sector and government organizations, using phishing lures, DLL sideloading, Toneshell, Claimloader, and the newly observed Havencode backdoor for reconnaissance, credential harvesting, interactive access, and document exfiltration.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.