Mustang Panda is a China-aligned cyberespionage threat associated in the provided content with a 2024 campaign reported by ESET targeting the maritime sector. In that campaign, the actor used USB devices to introduce malware onto air-gapped or segmented shipboard systems. The stated objective was espionage against vessels, specifically to spy on navigation and cargo data. The content ties this activity to shipboard operational environments and maritime targets, indicating use against systems on vessels rather than conventional enterprise-only networks. No specific malware family name, technical implant details, or indicators of compromise are provided in the content.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
In 2024, Eset reported on a targeted campaign by a China-aligned cyberespionage threat actor it tracks as Mustang Panda, that used USB sticks to get malware onto air-gapped or segmented shipboard systems, so it could spy on vessels navigation and cargo data.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Malware used in a China-aligned cyberespionage campaign to infect air-gapped or segmented shipboard systems via USB devices and collect navigation and cargo data.
Malware used in a targeted cyberespionage campaign to infiltrate air-gapped or segmented shipboard systems via USB devices and collect navigation and cargo data.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.