← Back to all threat actors

Mustang Panda

Also known as TA416, RedDelta, BRONZE PRESIDENT, STATELY TAURUS, FIREANT, CAMARO DRAGON, EARTH PRETA, HIVE0154, TWILL TYPHOON, TANTALUM, LUMINOUS MOTH, UNC6384, TEMP.Hex, Red Lich, ClumsyToad, Mustang Panda
Tracked as G0129

Mustang Panda is a China-based cyber espionage threat actor that has been conducting operations since at least 2012. Mustang Panda has been known to use tailored phishing lures and decoy documents to deliver malicious payloads. Mustang Panda has targeted government, diplomatic, and non-governmental organizations, including think tanks, religious institutions, and research entities, across the United States, Europe, and Asia, with notable activity in Russia, Mongolia, Myanmar, Pakistan, and Vietnam.

How we source and review actor profiles
Sectors
government, ngo, defense, research-academia
Status
Active

Threat intelligence assessment

At a glance

Facts

  • Threat actor known as HoneyMyte (aka Mustang Panda) deploys updated CoolClient backdoor with signed Windows kernel-mode rootkit

Activity timeline

Facts

  • Targeted victims in Myanmar, Mongolia, Pakistan, and Russia including confirmed government entities
  • Consistently deployed CoolClient as secondary backdoor following PlugX infection

Attribution assessment

Facts

  • HoneyMyte used PlugX as initial post-compromise implant to deploy CoolClient
  • HoneyMyte kernel-mode rootkit was used to load ToneShell backdoor in December 2025
  • The overall design of the new CoolClient driver is comparable to kernel-mode enhancements seen with ToneShell

Operational playbook

Facts

  • CoolClient deployed when has full access to Service Control Manager (SCM) and SeTcbPrivilege privilege
  • If conditions not met, malware skips driver deployment and proceeds to final-stage implant
  • Driver receives configuration from CoolClient user-mode component through IOCTL requests
  • CoolClient process registered as trusted process with driver to access protected files, registry keys, and processes

Initial access and identity targets

Facts

  • Uses PlugX as initial post-compromise implant to deploy CoolClient components

Capabilities and evasion

Facts

  • CoolClient supports keylogging, clipboard theft, credential harvesting, file management, system reconnaissance, and plugin-delivered functionality
  • Kernel driver can hide and protect malicious processes, files, registry objects, and C2 network information
  • Driver implements process hiding by unlinking entries from Windows active process list
  • Filesystem minifilter denies access to protected files and directories
  • Registry callback removes protected keys and values from enumeration results and blocks modification or deletion attempts
  • Separate hook in Windows Nsiproxy driver filters configured C2 IPv4 addresses from network information

Infrastructure patterns

Facts

  • msagent.sys driver is digitally signed with certificate issued to Nanjing Ranyi Technology Co., Ltd. valid from August 2013 to September 2014

Named victims

Organizations

  • Myanmar
  • Mongolia
  • Pakistan
  • Russia

Reported detail

Facts

  • HoneyMyte deployed an updated CoolClient backdoor with a signed Windows kernel-mode rootkit to provide stealth capabilities for hiding malicious processes, files, and C2 communications.
  • The malware uses PlugX as initial implant followed by CoolClient as secondary backdoor, targeting government entities in Myanmar, Mongolia, Pakistan, and Russia.
  • The rootkit driver (msagent.sys) communicates with CoolClient through IOCTL requests to protect specific processes, registry paths, and network information from detection.
  • The driver implements multiple stealth techniques including process hiding, filesystem filtering, registry hiding, and network address filtering through Nsiproxy hooks.
  • This represents an evolution of HoneyMyte's toolkit, with similar kernel-mode design patterns previously observed in their ToneShell backdoor deployment.

Activity timeline

A dated ledger of actor-claimed victims, campaigns, indicators, identity mappings, relationships, and CVE links. Each date states what it measures. For extensive leak-site histories, victim entries are limited to the 100 most recent distinct listings.

Cataloged
Indicator11 indicators cataloged

Types: md5, tool.

Cataloged
IdentityAlias: Mustang Panda

Reviewed identity mapping approved on this date.

Cataloged
IdentityAlias: TA416

Reviewed identity mapping approved on this date.

Cataloged
IdentityAlias: RedDelta

Reviewed identity mapping approved on this date.

Cataloged
IdentityAlias: BRONZE PRESIDENT

Reviewed identity mapping approved on this date.

Cataloged
IdentityAlias: STATELY TAURUS

Reviewed identity mapping approved on this date.

Cataloged
IdentityAlias: FIREANT

Reviewed identity mapping approved on this date.

Cataloged
IdentityAlias: CAMARO DRAGON

Reviewed identity mapping approved on this date.

Cataloged
IdentityAlias: EARTH PRETA

Reviewed identity mapping approved on this date.

Cataloged
IdentityAlias: HIVE0154

Reviewed identity mapping approved on this date.

Cataloged
IdentityAlias: TWILL TYPHOON

Reviewed identity mapping approved on this date.

Cataloged
IdentityAlias: TANTALUM

Reviewed identity mapping approved on this date.

Cataloged
IdentityAlias: LUMINOUS MOTH

Reviewed identity mapping approved on this date.

Cataloged
IdentityAlias: UNC6384

Reviewed identity mapping approved on this date.

Cataloged
IdentityAlias: TEMP.Hex

Reviewed identity mapping approved on this date.

Cataloged
IdentityAlias: Red Lich

Reviewed identity mapping approved on this date.

Cataloged
IdentityAlias: ClumsyToad

Reviewed identity mapping approved on this date.

Cataloged
IdentityTracking identifier: G0129

Reviewed identity mapping approved on this date.

First observed
CVECVE-2026-58231 linked to this actor

Mustang Panda Adds Signed Windows Rootkit to CoolClient Backdoor for Stealth

Last observed
CampaignRedDelta Modified PlugX Infection Chain Operations

RedDelta Modified PlugX Infection Chain Operations was executed by Mustang Panda from mid-2023 through the end of 2024 against multiple entities in East and Southeast Asia. [RedDelta Modified Pl…

Identity and attribution

Exact names and tracking identifiers resolve to this canonical profile. Rebrands, affiliations, and overlapping clusters remain separate confidence-rated relationships.

Name map

Mustang PandaCanonical Name
HoneyMyteCanonical Name
BRONZE PRESIDENTAlias
CAMARO DRAGONAlias
ClumsyToadAlias
EARTH PRETAAlias
FIREANTAlias
HIVE0154Alias
LUMINOUS MOTHAlias
Red LichAlias
RedDeltaAlias
STATELY TAURUSAlias
TA416Alias
TANTALUMAlias
TEMP.HexAlias
TWILL TYPHOONAlias
UNC6384Alias
Mustang PandaAlias
G0129Tracking Id

Shared-name reviews

Every exact-name collision is reviewed. Same-actor decisions select a preferred profile while distinct and unresolved clusters remain separate.

Identity remains unresolved medium

MITRE maintains LuminousMoth and Mustang Panda as separate group records while describing targeting, technique, and infrastructure overlap. The shared LUMINOUS MOTH name is not sufficient evidence of exact equivalence.

Loading CVEs, techniques, indicators, malware, victims, and activity...