Mustang Panda
Also tracked as TA416, RedDelta, BRONZE PRESIDENT, STATELY TAURUS, FIREANT, CAMARO DRAGON, EARTH PRETA, HIVE0154, TWILL TYPHOON, TANTALUM, LUMINOUS MOTH, UNC6384, TEMP.Hex, Red Lich, ClumsyToad
Mustang Panda is a China-based cyber espionage threat actor that has been conducting operations since at least 2012. Mustang Panda has been known to use tailored phishing lures and decoy documents to deliver malicious payloads. Mustang Panda has targeted government, diplomatic, and non-governmental organizations, including think tanks, religious institutions, and research entities, across the United States, Europe, and Asia, with notable activity in Russia, Mongolia, Myanmar, Pakistan, and Vietnam.
- Documented techniques
- 85
- Assessed origin
- China
- Assessed motivation
- Espionage
- First seen
- 2012
- Basis
- MITRE ATT&CK
How they break in
Techniques MITRE has documented this group using, grouped by the stage of an attack they belong to. This is the actionable half: each one is a behaviour you can look for in your own logs, and a control you can test.
resource development10
execution13
- T1047 Windows Management Instrumentation
- T1053.005 Scheduled Task
- T1059 Command and Scripting Interpreter
- T1059.001 PowerShell
- T1059.003 Windows Command Shell
- T1059.005 Visual Basic
- T1059.007 JavaScript
- T1072 Software Deployment Tools
- T1106 Native API
- T1129 Shared Modules
- T1203 Exploitation for Client Execution
- T1204.001 Malicious Link
- T1204.002 Malicious File
privilege escalation1
credential access5
discovery11
- T1016 System Network Configuration Discovery
- T1018 Remote System Discovery
- T1046 Network Service Discovery
- T1049 System Network Connections Discovery
- T1057 Process Discovery
- T1069.002 Domain Groups
- T1082 System Information Discovery
- T1083 File and Directory Discovery
- T1087.002 Domain Account
- T1518 Software Discovery
- T1654 Log Enumeration
lateral movement1
collection4
command and control9
exfiltration4
defense impairment1
stealth19
- T1027 Obfuscated Files or Information
- T1027.007 Dynamic API Resolution
- T1027.012 LNK Icon Smuggling
- T1027.016 Junk Code Insertion
- T1036.005 Match Legitimate Resource Name or Location
- T1036.007 Double File Extension
- T1036.008 Masquerade File Type
- T1070 Indicator Removal
- T1070.004 File Deletion
- T1070.006 Timestomp
- T1140 Deobfuscate/Decode Files or Information
- T1205 Traffic Signaling
- T1218.004 InstallUtil
- T1218.005 Mshta
- T1564.001 Hidden Files and Directories
- T1574.001 DLL
- T1574.005 Executable Installer File Permissions Weakness
- T1622 Debugger Evasion
- T1678 Delay Execution
Malware
Families MITRE records this group deploying. Detection names for these are a reasonable place to start.
Tools
Legitimate or dual-use software the group is documented using. Most of it is software your own administrators use too, which is the point.