Also known as TA416, RedDelta, BRONZE PRESIDENT, STATELY TAURUS, FIREANT, CAMARO DRAGON, EARTH PRETA, HIVE0154, TWILL TYPHOON, TANTALUM, LUMINOUS MOTH, UNC6384, TEMP.Hex, Red Lich, ClumsyToad, Mustang Panda
Tracked asG0129
Mustang Panda is a China-based cyber espionage threat actor that has been conducting operations since at least 2012. Mustang Panda has been known to use tailored phishing lures and decoy documents to deliver malicious payloads. Mustang Panda has targeted government, diplomatic, and non-governmental organizations, including think tanks, religious institutions, and research entities, across the United States, Europe, and Asia, with notable activity in Russia, Mongolia, Myanmar, Pakistan, and Vietnam.
Threat actor known as HoneyMyte (aka Mustang Panda) deploys updated CoolClient backdoor with signed Windows kernel-mode rootkit
Activity timeline
Facts
Targeted victims in Myanmar, Mongolia, Pakistan, and Russia including confirmed government entities
Consistently deployed CoolClient as secondary backdoor following PlugX infection
Attribution assessment
Facts
HoneyMyte used PlugX as initial post-compromise implant to deploy CoolClient
HoneyMyte kernel-mode rootkit was used to load ToneShell backdoor in December 2025
The overall design of the new CoolClient driver is comparable to kernel-mode enhancements seen with ToneShell
Operational playbook
Facts
CoolClient deployed when has full access to Service Control Manager (SCM) and SeTcbPrivilege privilege
If conditions not met, malware skips driver deployment and proceeds to final-stage implant
Driver receives configuration from CoolClient user-mode component through IOCTL requests
CoolClient process registered as trusted process with driver to access protected files, registry keys, and processes
Initial access and identity targets
Facts
Uses PlugX as initial post-compromise implant to deploy CoolClient components
Capabilities and evasion
Facts
CoolClient supports keylogging, clipboard theft, credential harvesting, file management, system reconnaissance, and plugin-delivered functionality
Kernel driver can hide and protect malicious processes, files, registry objects, and C2 network information
Driver implements process hiding by unlinking entries from Windows active process list
Filesystem minifilter denies access to protected files and directories
Registry callback removes protected keys and values from enumeration results and blocks modification or deletion attempts
Separate hook in Windows Nsiproxy driver filters configured C2 IPv4 addresses from network information
Infrastructure patterns
Facts
msagent.sys driver is digitally signed with certificate issued to Nanjing Ranyi Technology Co., Ltd. valid from August 2013 to September 2014
Named victims
Organizations
Myanmar
Mongolia
Pakistan
Russia
Reported detail
Facts
HoneyMyte deployed an updated CoolClient backdoor with a signed Windows kernel-mode rootkit to provide stealth capabilities for hiding malicious processes, files, and C2 communications.
The malware uses PlugX as initial implant followed by CoolClient as secondary backdoor, targeting government entities in Myanmar, Mongolia, Pakistan, and Russia.
The rootkit driver (msagent.sys) communicates with CoolClient through IOCTL requests to protect specific processes, registry paths, and network information from detection.
The driver implements multiple stealth techniques including process hiding, filesystem filtering, registry hiding, and network address filtering through Nsiproxy hooks.
This represents an evolution of HoneyMyte's toolkit, with similar kernel-mode design patterns previously observed in their ToneShell backdoor deployment.
Activity timeline
A dated ledger of actor-claimed victims, campaigns, indicators, identity mappings, relationships, and CVE links. Each date states what it measures. For extensive leak-site histories, victim entries are limited to the 100 most recent distinct listings.
Cataloged
Indicator11 indicators cataloged
Types: md5, tool.
Cataloged
IdentityAlias: Mustang Panda
Reviewed identity mapping approved on this date.
Cataloged
IdentityAlias: TA416
Reviewed identity mapping approved on this date.
Cataloged
IdentityAlias: RedDelta
Reviewed identity mapping approved on this date.
Cataloged
IdentityAlias: BRONZE PRESIDENT
Reviewed identity mapping approved on this date.
Cataloged
IdentityAlias: STATELY TAURUS
Reviewed identity mapping approved on this date.
Cataloged
IdentityAlias: FIREANT
Reviewed identity mapping approved on this date.
Cataloged
IdentityAlias: CAMARO DRAGON
Reviewed identity mapping approved on this date.
Cataloged
IdentityAlias: EARTH PRETA
Reviewed identity mapping approved on this date.
Cataloged
IdentityAlias: HIVE0154
Reviewed identity mapping approved on this date.
Cataloged
IdentityAlias: TWILL TYPHOON
Reviewed identity mapping approved on this date.
Cataloged
IdentityAlias: TANTALUM
Reviewed identity mapping approved on this date.
Cataloged
IdentityAlias: LUMINOUS MOTH
Reviewed identity mapping approved on this date.
Cataloged
IdentityAlias: UNC6384
Reviewed identity mapping approved on this date.
Cataloged
IdentityAlias: TEMP.Hex
Reviewed identity mapping approved on this date.
Cataloged
IdentityAlias: Red Lich
Reviewed identity mapping approved on this date.
Cataloged
IdentityAlias: ClumsyToad
Reviewed identity mapping approved on this date.
Cataloged
IdentityTracking identifier: G0129
Reviewed identity mapping approved on this date.
First observed
CVECVE-2026-58231 linked to this actor
Mustang Panda Adds Signed Windows Rootkit to CoolClient Backdoor for Stealth
RedDelta Modified PlugX Infection Chain Operations was executed by Mustang Panda from mid-2023 through the end of 2024 against multiple entities in East and Southeast Asia. [RedDelta Modified Pl…
Identity and attribution
Exact names and tracking identifiers resolve to this canonical profile. Rebrands, affiliations, and overlapping clusters remain separate confidence-rated relationships.
Name map
Mustang PandaCanonical Name
HoneyMyteCanonical Name
BRONZE PRESIDENTAlias
CAMARO DRAGONAlias
ClumsyToadAlias
EARTH PRETAAlias
FIREANTAlias
HIVE0154Alias
LUMINOUS MOTHAlias
Red LichAlias
RedDeltaAlias
STATELY TAURUSAlias
TA416Alias
TANTALUMAlias
TEMP.HexAlias
TWILL TYPHOONAlias
UNC6384Alias
Mustang PandaAlias
G0129Tracking Id
Shared-name reviews
Every exact-name collision is reviewed. Same-actor decisions select a preferred profile while distinct and unresolved clusters remain separate.
MITRE maintains LuminousMoth and Mustang Panda as separate group records while describing targeting, technique, and infrastructure overlap. The shared LUMINOUS MOTH name is not sufficient evidence of exact equivalence.
Loading CVEs, techniques, indicators, malware, victims, and activity...