Mustang Panda
Mustang Panda is a China-based cyber espionage threat actor that has been conducting operations since at least 2012. Mustang Panda has been known to use tailored phishing lures and decoy documents to deliver malicious...
RedDelta Modified PlugX Infection Chain Operations was executed by Mustang Panda from mid-2023 through the end of 2024 against multiple entities in East and Southeast Asia. RedDelta Modified PlugX Infection Chain Operations involved phishing to deliver malicious files or links to users prompting follow-on installer downloads to load PlugX on victim machines in a persistent state.
Each relationship retains its own confidence and source.
Mustang Panda is a China-based cyber espionage threat actor that has been conducting operations since at least 2012. Mustang Panda has been known to use tailored phishing lures and decoy documents to deliver malicious...
Every date says what it measures so catalog dates are not confused with publication dates.
Attribution confidence: Source Reported.
The campaign source marks this as the latest known activity date.
The campaign source marks this as the beginning of the known activity window.
CVEs, techniques, malware, and indicators in the sections below are associated with an attributed actor. They are useful investigative context, but the campaign source does not necessarily link every item directly to this campaign.
Use this material to guide hunting and prioritization, then confirm each relationship against its cited source.
2d7c8780e97409770a9d4f31c66c9d63MD5 | Mustang Panda9460e150e1981d5c165043520c5c12feMD5 | Mustang Panda9717f005c5fb98e08d2ad983d88f94eeMD5 | Mustang PandaCoolClientTOOL | Mustang PandaPlugXTOOL | Mustang PandaToneShellTOOL | Mustang Pandacert.iniTOOL | Mustang Pandaf518d8e5fe70d9090f6280c68a95998fMD5 | Mustang Pandalibngs.dllTOOL | Mustang Pandaloadcert.iniTOOL | Mustang Pandamsagent.sysTOOL | Mustang PandaOpen the original material before making an attribution or response decision.