Threat Intelligence / Actor / Mustang Panda
Mustang Panda
As of 2026-09-02, Mustang Panda is a China-nexus threat actor tracked by Threadlinqs Intelligence across 14 threats spanning apt, malware, supply chain. Also known as Twill Typhoon, HoneyMyte, BRONZE PRESIDENT, CAMARO DRAGON. ATT&CK coverage spans 128 techniques across 16 tactics in 14 of 14 tracked threats. Most-observed techniques: T1140 (Deobfuscate/Decode Files or Information), T1027 (Obfuscated Files or Information), T1082 (System Information Discovery).
Also known as: Twill Typhoon, HoneyMyte, BRONZE PRESIDENT, CAMARO DRAGON, ClumsyToad, EARTH PRETA, FIREANT, HIVE0154, LUMINOUS MOTH, Red Lich, RedDelta, STATELY TAURUS
ATT&CK techniques observed
- T1140 Deobfuscate/Decode Files or Information — Defense Evasion — observed in 11 of 14 tracked threats
- T1027 Obfuscated Files or Information — Defense Evasion — observed in 10 of 14 tracked threats
- T1082 System Information Discovery — Discovery — observed in 10 of 14 tracked threats
- T1105 Ingress Tool Transfer — Command And Control — observed in 9 of 14 tracked threats
- T1036 Masquerading — Defense Evasion — observed in 8 of 14 tracked threats
- T1041 Exfiltration Over C2 Channel — Exfiltration — observed in 8 of 14 tracked threats
- T1071 Application Layer Protocol — Command And Control — observed in 8 of 14 tracked threats
- T1106 Native API — Execution — observed in 8 of 14 tracked threats
- T1574 Hijack Execution Flow — Defense Evasion — observed in 8 of 14 tracked threats
- T1005 Data from Local System — Collection — observed in 7 of 14 tracked threats
- T1059 Command and Scripting Interpreter — Execution — observed in 7 of 14 tracked threats
- T1547 Boot or Logon Autostart Execution — Persistence — observed in 7 of 14 tracked threats
- T1573 Encrypted Channel — Command And Control — observed in 7 of 14 tracked threats
- T1083 File and Directory Discovery — Discovery — observed in 6 of 14 tracked threats
- T1204 User Execution — Execution — observed in 6 of 14 tracked threats
Tracked threats
- Mustang Panda Targets India's Government and Energy Sectors with SHARDLOADER, MINIRECON, and ZOHOMURK — HIGH
- HoneyMyte (Mustang Panda) Upgrades CoolClient Backdoor with Kernel-Level Windows Rootkit (msagent.sys) — HIGH
- QuickFox Supply Chain Attack Deploys FDMTP Implant via Trojanized VPN Proxy/Game Accelerator — MEDIUM
- SolidPDFCreator: Mustang Panda Stage-1 Backdoor Targeting India via DLL Side-Loading — HIGH
- ASEC June 2026 APT Trend Report: Nation-State Actors Pivot to Cloud/OAuth Abuse, MaaS, and Supply-Chain Compromise — MEDIUM
- AhnLab ASEC April 2026 APT Group Trend Report: State-Sponsored Espionage Campaigns (CVE-2026-32202, CVE-2025-20333/20362, CVE-2021-26855) — HIGH
- Mustang Panda PlugX RAT — Multi-Stage Fake Browser Update Chain via G DATA AntiVirus DLL Sideloading (BlueCyber) — HIGH
- Mustang Panda LOTUSLITE v1.1 Espionage Campaign Targets Indian Banking (HDFC) and South Korean Policy Circles — HIGH
- Fake Claude AI Download Site Delivers Trojanized Installer Deploying PlugX RAT via G DATA DLL Sideloading — HIGH
- China-Aligned Espionage Clusters (Stately Taurus, CL-STA-1048, CL-STA-1049) Deploy USBFect, Masol RAT, FluffyGh0st and Custom Loaders Against Southeast Asian Government — HIGH
- Mustang Panda Deploys PlugX RAT via Multi-Stage CHM Sideloading Campaign Targeting Persian Gulf Region (March 2026) — HIGH
- HoneyMyte (Mustang Panda) CoolClient Backdoor Update with Browser Data Stealers Targeting Southeast Asian Government and Military — HIGH
- Mustang Panda LOTUSLITE Backdoor & StealC Campaigns Exploiting Middle East Conflict Themes — HIGH
- PlugX Meeting Invitation Campaign — China-Nexus MSBuild LOLBIN + GDATA DLL Sideloading, RC4 Encrypted C2, STATICPLUGIN Variant (Mustang Panda / UNC6384) — HIGH
Related CVEs
CVE-2026-32202, CVE-2026-21509, CVE-2025-20362, CVE-2025-20333, CVE-2021-26855
Full actor intelligence — infrastructure, IOCs, detection coverage and operator fingerprints — is available via the Threadlinqs MCP server (Purple tier). View plans →