Mustang Panda

APT / StateG0129 ↗
Origin🇨🇳 China
Techniques (MITRE ATT&CK)85
SourceMITRE ATT&CK
State sponsor: ChinaAttribution confidence: 50%Target categories: Civil society
Targeted regions: United States · Germany
Also known as:BASINBASIN CASTLEBRONZE PRESIDENTCAMARO DRAGONClumsyToadEARTH PRETAEarth PretaFIREANTHIVE0154Hive0154HoneyMyteITG27LUMINOUS MOTHLuminousMothPolarisRed LichRedDeltaSTATELY TAURUSStately TaurusTA416TANTALUMTEMP.HEXTEMP.HexTWILL TYPHOONTwill TyphoonUNC6384UNK_SteadySplit

About the group

Mustang Panda is a China-based cyber espionage threat actor that has been conducting operations since at least 2012. Mustang Panda has been known to use tailored phishing lures and decoy documents to deliver malicious payloads. Mustang Panda has targeted government, diplomatic, and non-governmental organizations, including think tanks, religious institutions, and research entities, across the United States, Europe, and Asia, with notable activity in Russia, Mongolia, Myanmar, Pakistan, and Vietnam.

Attack chain

Plausible scenario built from the group's real techniques, ordered by the phases of an attack. Each step shows how the group typically operates.

Arsenal severity82
Impact: High
T1566.001T1047T1176.002T1546.003T1091T1074.001ENTRYInitial accessSpearphishingAttachmentEXECExecutionWindows ManagementInstrumentationPERSPersistenceIDE ExtensionsPRIVPrivilege escalationWindows ManagementInstrumentation E…LATLateral movementReplicationThrough Removable…COLLCollectionLocal Data StagingEXFILExfiltrationExfiltration OverC2 Channel

Illustrative chain derived from techniques documented in MITRE ATT&CK — it does not represent a specific past attack. Severity summarizes the known arsenal (kill-chain coverage, actively exploited CVEs, techniques).

Techniques (MITRE ATT&CK) 85

How the group operates, mapped to the MITRE ATT&CK matrix and organized by the phases of an attack.

defense-impairment

Exploited vulnerabilities 1

CVEs this group is known to exploit, per MITRE ATT&CK. Ordered by real-world severity.

Known infrastructure 2996

Real indicators (C2, domains, URLs and hashes) associated with the malware this group uses. Source: abuse.ch (ThreatFox, URLhaus, MalwareBazaar).

ip:port114.215.184.158:8000Cobalt Strikethreatfox
urlhttp://69.49.229.88:443/MQEwCobalt Strikethreatfox
ip:port154.12.17.20:8080Cobalt Strikethreatfox
ip:port154.12.17.20:22Cobalt Strikethreatfox
ip:port154.12.17.20:443Cobalt Strikethreatfox
ip:port154.12.17.20:80Cobalt Strikethreatfox
ip:port129.204.55.230:443Cobalt Strikethreatfox
ip:port47.94.56.71:8080Cobalt Strikethreatfox
ip:port47.94.56.71:80Cobalt Strikethreatfox
ip:port47.94.56.71:443Cobalt Strikethreatfox
ip:port45.227.253.132:8080Cobalt Strikethreatfox
ip:port45.227.253.132:80Cobalt Strikethreatfox
ip:port45.227.253.132:443Cobalt Strikethreatfox
ip:port45.227.253.132:32775Cobalt Strikethreatfox
ip:port117.158.148.164:65535Cobalt Strikethreatfox
ip:port38.76.190.209:8888Cobalt Strikethreatfox
ip:port188.227.14.105:8080Cobalt Strikethreatfox
ip:port186.241.115.168:12443Cobalt Strikethreatfox
ip:port109.206.247.245:10881Cobalt Strikethreatfox
ip:port43.134.112.45:7500Cobalt Strikethreatfox
ip:port43.134.112.45:7000Cobalt Strikethreatfox
ip:port43.134.112.45:80Cobalt Strikethreatfox
ip:port43.134.112.45:8080Cobalt Strikethreatfox
ip:port43.134.112.45:443Cobalt Strikethreatfox
ip:port43.134.112.45:22Cobalt Strikethreatfox
ip:port101.34.208.175:18317Cobalt Strikethreatfox
sha1_hash2ff26540ebb9100dae76a2ae040108ba9338113cCobalt Strikethreatfox
md5_hashe4a34372eab0832d0682fa986a8e0b97Cobalt Strikethreatfox
sha256_hash35afe2df347cb0909fdf2aba8ed6a506a681518a98c0a723b25a16957437f944Cobalt Strikethreatfox
sha256_hash224aec5fec1f907ce152895095f56a3a2f2db0d627633ee691af56a13f34e7f8Cobalt Strikethreatfox

+2996 indicators in total. See them all on the IOCs page.

Mustang Panda uses real techniques and exploits real flaws. TrueHacking's AI Autonomous Pentest simulates these attacks against your infrastructure and brings more security to your application.

Explore the AI Autonomous Pentest →