Vexday analysis
Mustang Panda é um agente de espionagem cibernética de origem chinesa com operações documentadas desde pelo menos 2012, identificado no MITRE ATT&CK como G0129. O grupo é conhecido pelo uso de iscas de phishing direcionadas e documentos-isca para entrega de cargas maliciosas, tendo como alvos organizações governamentais, diplomáticas e não governamentais — incluindo think tanks, instituições religiosas e entidades de pesquisa — nos Estados Unidos, Europa e Ásia, com atividade notável na Rússia, Mongólia, Myanmar, Paquistão e Vietnã. Rastreado também pelos aliases TA416, RedDelta, BRONZE PRESIDENT, STATELY TAURUS, FIREANT e CAMARO DRAGON, o grupo acumula 85 técnicas documentadas no MITRE ATT&CK e tem uma CVE atribuída ao seu arsenal.
Attack chain
Plausible scenario built from the group's real techniques, ordered by the phases of an attack. Each step shows how the group typically operates.
Illustrative chain derived from techniques documented in MITRE ATT&CK — it does not represent a specific past attack. Severity summarizes the known arsenal (kill-chain coverage, actively exploited CVEs, techniques).
Techniques (MITRE ATT&CK) 85
How the group operates, mapped to the MITRE ATT&CK matrix and organized by the phases of an attack.
Exploited vulnerabilities 1
CVEs this group is known to exploit, per MITRE ATT&CK. Ordered by real-world severity.
Known infrastructure 1526
Real indicators (C2, domains, URLs and hashes) associated with the malware this group uses. Source: abuse.ch (ThreatFox, URLhaus, MalwareBazaar).
45.221.118.46:80Cobalt Strikethreatfox45.221.118.46:443Cobalt Strikethreatfox38.76.183.197:8082Cobalt Strikethreatfox8.222.188.173:443Cobalt Strikethreatfox8.219.220.240:7777Cobalt Strikethreatfox209.99.184.234:50050Cobalt Strikethreatfox120.77.42.217:50000Cobalt Strikethreatfox49.235.52.47:3000Cobalt Strikethreatfox49.235.52.47:8080Cobalt Strikethreatfox49.235.52.47:80Cobalt Strikethreatfox49.235.52.47:443Cobalt Strikethreatfox49.235.52.47:8083Cobalt Strikethreatfox147.139.136.105:8080Cobalt Strikethreatfox38.207.177.165:8080Cobalt Strikethreatfox147.139.136.105:80Cobalt Strikethreatfox147.139.136.105:22Cobalt Strikethreatfox147.139.136.105:443Cobalt Strikethreatfox2.57.241.129:80Cobalt Strikethreatfox38.207.177.165:80Cobalt Strikethreatfox38.207.177.165:443Cobalt Strikethreatfox147.139.245.149:801Cobalt Strikethreatfox45.221.118.46:8080Cobalt Strikethreatfox119.45.198.250:55555Cobalt Strikethreatfox118.24.42.214:443Cobalt Strikethreatfox47.251.29.219:50050Cobalt Strikethreatfox47.254.68.68:50050Cobalt Strikethreatfox172.232.97.189:4444Cobalt Strikethreatfox149.88.66.234:21Cobalt Strikethreatfox47.108.86.120:22Cobalt Strikethreatfox47.108.86.120:111Cobalt Strikethreatfox+1526 indicators in total. See them all on the IOCs page.
References
Mustang Panda uses real techniques and exploits real flaws. TrueHacking's AI Autonomous Pentest simulates these attacks against your infrastructure and brings more security to your application.
Explore the AI Autonomous Pentest →