All actors

Mustang Panda

Also reported as TA416, RedDelta, BRONZE PRESIDENT, TANTALUM, Red Lich and 27 other names. Linked to China by four sources.

Reports
1,014
Last reported
Known CVEs
350
Techniques in ATT&CK
85
Origin
China
ID
G0129
Merge evidence
49 alias matches

Reports per quarter

  1. 2007 Q4: 1 report
  2. 2008 Q1: no reports
  3. 2008 Q2: no reports
  4. 2008 Q3: no reports
  5. 2008 Q4: no reports
  6. 2009 Q1: no reports
  7. 2009 Q2: no reports
  8. 2009 Q3: no reports
  9. 2009 Q4: no reports
  10. 2010 Q1: no reports
  11. 2010 Q2: 1 report
  12. 2010 Q3: no reports
  13. 2010 Q4: no reports
  14. 2011 Q1: no reports
  15. 2011 Q2: no reports
  16. 2011 Q3: 2 reports
  17. 2011 Q4: no reports
  18. 2012 Q1: no reports
  19. 2012 Q2: no reports
  20. 2012 Q3: no reports
  21. 2012 Q4: no reports
  22. 2013 Q1: 3 reports
  23. 2013 Q2: 2 reports
  24. 2013 Q3: 1 report
  25. 2013 Q4: no reports
  26. 2014 Q1: no reports
  27. 2014 Q2: no reports
  28. 2014 Q3: 1 report
  29. 2014 Q4: 2 reports
  30. 2015 Q1: no reports
  31. 2015 Q2: 2 reports
  32. 2015 Q3: 2 reports
  33. 2015 Q4: 1 report
  34. 2016 Q1: no reports
  35. 2016 Q2: 3 reports
  36. 2016 Q3: 1 report
  37. 2016 Q4: 1 report
  38. 2017 Q1: no reports
  39. 2017 Q2: 7 reports
  40. 2017 Q3: 3 reports
  41. 2017 Q4: 1 report
  42. 2018 Q1: 2 reports
  43. 2018 Q2: 8 reports
  44. 2018 Q3: 5 reports
  45. 2018 Q4: 3 reports
  46. 2019 Q1: 4 reports
  47. 2019 Q2: 11 reports
  48. 2019 Q3: 3 reports
  49. 2019 Q4: 18 reports
  50. 2020 Q1: 27 reports
  51. 2020 Q2: 19 reports
  52. 2020 Q3: 29 reports
  53. 2020 Q4: 44 reports
  54. 2021 Q1: 59 reports
  55. 2021 Q2: 63 reports
  56. 2021 Q3: 75 reports
  57. 2021 Q4: 54 reports
  58. 2022 Q1: 71 reports
  59. 2022 Q2: 86 reports
  60. 2022 Q3: 57 reports
  61. 2022 Q4: 32 reports
  62. 2023 Q1: 31 reports
  63. 2023 Q2: 17 reports
  64. 2023 Q3: 23 reports
  65. 2023 Q4: 21 reports
  66. 2024 Q1: 14 reports
  67. 2024 Q2: 21 reports
  68. 2024 Q3: 24 reports
  69. 2024 Q4: 15 reports
  70. 2025 Q1: 15 reports
  71. 2025 Q2: 9 reports
  72. 2025 Q3: 13 reports
  73. 2025 Q4: 7 reports
  74. 2026 Q1: 8 reports
  75. 2026 Q2: 88 reports
  76. 2026 Q3: 4 reports
Dated reports, 2007 Q4 to 2026 Q3.

Techniques seen in the last two years

Show all 309 techniques Show fewer

Counts come from technique IDs in the actor's report text. “Reports only” means reports name the technique but MITRE ATT&CK® does not list it for this actor.

Also listed by ATT&CK

Show all 18 techniques Show fewer

CVEs named in reports

Show all 350 CVEs Show fewer

KEV marks a CVE in CISA's Known Exploited Vulnerabilities Catalog, and “ransomware” marks one that the catalog records as used in ransomware campaigns.

Reports

  1. Bankshot (Malware Family)

    date ORKL added it fromORKL

Show all 1,014 reports Show fewer
  1. StoneDrill (Malware Family)

    date ORKL added it fromORKL

  2. Threat Group Cards: A Threat Actor Encyclopedia

    date ORKL added it fromORKL

  3. ShadowPad (Malware Family)

    date ORKL added it fromORKL

  4. ISFB (Malware Family)

    date ORKL added it fromORKL

  5. Gandcrab (Malware Family)

    date ORKL added it fromORKL

  6. HermeticWiper (Malware Family)

    date ORKL added it fromORKL

  7. Crimson RAT (Malware Family)

    date ORKL added it fromORKL

  8. Oblique RAT (Malware Family)

    date ORKL added it fromORKL

  9. METALJACK (Malware Family)

    date ORKL added it fromORKL

  10. elf.wellmess (Malware Family)

    date ORKL added it fromORKL

  11. SUNBURST (Malware Family)

    date ORKL added it fromORKL

  12. Threat Group Cards: A Threat Actor Encyclopedia

    date ORKL added it fromORKL

  13. CHINACHOPPER (Malware Family)

    date ORKL added it fromORKL

  14. FlawedAmmyy (Malware Family)

    date ORKL added it fromORKL

  15. QakBot (Malware Family)

    date ORKL added it fromORKL

  16. Poison Ivy (Malware Family)

    date ORKL added it fromORKL

  17. REvil (Malware Family)

    date ORKL added it fromORKL

  18. Dridex (Malware Family)

    date ORKL added it fromORKL

  19. WhisperGate (Malware Family)

    date ORKL added it fromORKL

  20. PlugX (Malware Family)

    date ORKL added it fromORKL

  21. PowGoop (Malware Family)

    date ORKL added it fromORKL

  22. Cobalt Strike (Malware Family)

    date ORKL added it fromORKL

  23. Ryuk (Malware Family)

    date ORKL added it fromORKL

  24. Maze (Malware Family)

    date ORKL added it fromORKL

  25. Threat Group Cards: A Threat Actor Encyclopedia

    date ORKL added it fromORKL

  26. PartyTicket (Malware Family)

    date ORKL added it fromORKL

  27. BlackSuit Ransomware

    publisher's date The DFIR Report fromORKLDFIR Report

  28. hodur_recon2024.pdf

    Malpedia library date fromORKL

  29. chinese-apts-target-asean-entities-jp

    date ORKL added it fromORKL

  30. chinese-apts-target-asean-entities-en

    date ORKL added it fromORKL

  31. watchtower-2023-eoy-report-en

    file creation date fromORKL

  32. Modern Asia APT groups TTPs

    file creation date Kaspersky fromORKL

  33. New Mustang Panda’s campaing against Australia

    date in the title fromORKL

  34. A border-hopping PlugX USB worm takes its act on the road

    date in the title fromORKL

  35. Diving into a PlugX sample of Mustang Panda group

    date in the title fromORKL

  36. Hitching a ride with Mustang Panda

    date in the title fromORKL

  37. Evolution of the PlugX loader

    date in the title fromORKL

  38. Earth Preta Spear-Phishing Governments Worldwide

    date in the title fromORKL

  39. Family Tree- DLL-Sideloading Cases May Be Related

    date in the title fromORKL

  40. Mustang Panda Abuses Legitimate Apps to Target Myanmar Based Victims

    date in the CCS '25 data BlackBerry fromORKLCCS '25 data

  41. BumbleBee: Round Two

    publisher's date The DFIR Report fromORKLDFIR Report

  42. Hunting for Unsigned DLLs to Find APTs

    date in the title fromORKL

  43. RedSense

    Malpedia library date fromORKL

  44. BRONZE PRESIDENT Targets Government Officials _ Secureworks

    date in the CCS '25 data SecureWorks fromORKLCCS '25 data

  45. BRONZE PRESIDENT Targets Government Officials

    date in the title fromORKL

  46. APT trends report Q2 2020

    date in the title fromORKL

  47. RedSense

    Malpedia library date fromORKL

  48. CERT-UA

    Malpedia library date fromORKL

  49. CERT-UA

    Malpedia library date fromORKL

  50. CB_941_Canhbao_APT_36c5a857fa.pdf

    Malpedia library date Socialist Republic of Vietnam fromORKLCCS '25 data

  51. RedSense

    Malpedia library date fromORKL

  52. [QuickNote] CobaltStrike SMB Beacon Analysis

    date in the title fromORKL

  53. eset_threat_report_t12022

    file creation date fromORKL

  54. Chinese Naikon Group Back with New Espionage Attack

    date in the title fromORKL

  55. yir-cyber-threats-annex-download.pdf

    Malpedia library date fromORKL

  56. Quantum Ransomware

    publisher's date The DFIR Report fromORKLDFIR Report

  57. RedSense

    Malpedia library date fromORKL

  58. New spear phishing campaign targets Russian dissidents

    file creation date malwarebytes fromORKL

  59. New spear phishing campaign targets Russian dissidents

    date in the title fromORKL

  60. Mustang Panda's Hodur- Old stuff, new variant of Korplug

    date in the title fromORKL

  61. New Mustang Panda hacking campaign targets diplomats, ISPs

    date in the title fromORKL

  62. Mustang Panda’s Hodur_ Old tricks, new Korplug variant _ WeLiveSecurity

    date in the CCS '25 data ESET fromORKLCCS '25 data

  63. Mustang Panda’s Hodur- Old tricks, new Korplug variant

    date in the title fromORKL

  64. CERT-UA

    Malpedia library date fromORKL

  65. 2021 Year In Review

    publisher's date The DFIR Report fromORKLDFIR Report

  66. 2021trends.pdf

    Malpedia library date fromORKL

  67. RedSense

    Malpedia library date fromORKL

  68. eset_jumping_the_air_gap_wp

    Malpedia library date ESET fromORKLCCS '25 data

  69. BlackMatter, LockBit, and THOR

    date in the title fromORKL

  70. From Zero to Domain Admin

    publisher's date The DFIR Report fromORKLDFIR Report

  71. RedSense

    Malpedia library date fromORKL

  72. report-old-dogs-new-tricks.pdf

    Malpedia library date fromORKL

  73. LuminousMoth APT: Sweeping attacks for the chosen few

    date in the CCS '25 data Kaspersky fromORKLCCS '25 data

  74. LuminousMoth APT- Sweeping attacks for the chosen few

    date in the title fromORKL

  75. Ryuk Ransomware Now Targeting Webservers

    Malpedia library date fromORKL

  76. Geopolitical nation-state threat actor overview June 2021

    date in the title fromORKL

  77. Mustang Panda PlugX - 45.251.240.55 Pivot

    date in the title fromORKL

  78. Mustang Panda PlugX - 45.251.240.55 Pivot

    Malpedia library date fromORKL

  79. Conti Ransomware

    publisher's date The DFIR Report fromORKLDFIR Report

  80. CTIR_casestudy_2.pdf

    file creation date fromORKL

  81. CTIR_casestudy_1.pdf

    file creation date fromORKL

  82. the-operations-of-winnti-group.pdf

    Malpedia library date fromORKL

  83. A .NET rat targets Mongolia

    date in the title fromORKL

  84. report-bb-2021-threat-report.pdf

    Malpedia library date fromORKL

  85. Technical Analysis of Operation Diànxùn

    Malpedia library date fromORKL

  86. Bazar Drops the Anchor

    publisher's date The DFIR Report fromORKLDFIR Report

  87. Bazar, No Ryuk?

    publisher's date The DFIR Report fromORKLDFIR Report

  88. CrimsonIAS- Listening for an 3v1l User

    date in the title fromORKL

  89. Attack from Mustang Panda- My rabbit is back!

    date in the title fromORKL

  90. nao-sec.org-Royal Road ReDive

    date in the CCS '25 data nao_sec fromORKLCCS '25 data

  91. Royal Road! Re-Dive

    date in the title fromORKL

  92. China cyber attacks- the current threat landscape

    date in the title fromORKL

  93. Group-IB_Hi-Tech_Crime_Trends_2020-2021_en

    file creation date fromORKL

  94. Ryuk in 5 Hours

    publisher's date The DFIR Report fromORKLDFIR Report

  95. Ryuk's Return

    publisher's date The DFIR Report fromORKLDFIR Report

  96. APT_trends_report_Q2_2020_Securelist

    file creation date fromORKL

  97. ESET_Threat_Report_Q22020

    file creation date fromORKL

  98. APT trends report Q2 2020

    date in the title fromORKL

  99. Reverse Engineering the New Mustang Panda PlugX Downloader

    date in the title fromORKL

  100. Unknown China-Based APT Targeting Myanmarese Entities

    date in the title fromORKL

  101. Reverse Engineering the Mustang Panda PlugX Loader

    date in the title fromORKL

  102. Ursnif via LOLbins

    publisher's date The DFIR Report fromORKLDFIR Report

  103. 200407-MWB-COVID-White-Paper_Final

    date in the CCS '25 data Malwarebytes fromORKLCCS '25 data

  104. Catching APT41 exploiting a zero-day vulnerability

    date in the CCS '25 data Darktrace fromCCS '25 data

  105. Mustang Panda joins the COVID-19 bandwagon

    date in the title fromORKL

  106. Is APT 27 Abusing COVID-19 To Attack People !

    date in the CCS '25 data Yoroi fromCCS '25 data

  107. APT36 jumps on the coronavirus bandwagon, delivers Crimson RAT _ Malwarebytes Labs

    date in the CCS '25 data Malwarebytes fromORKLCCS '25 data

  108. New wave of PlugX targets Hong Kong

    date in the title fromORKL

  109. BRONZE PRESIDENT Targets NGOs

    date in the title fromORKL

  110. BRONZE PRESIDENT Targets NGOs

    date in the CCS '25 data SecureWorks fromORKLCCS '25 data

  111. Aarhus_miniseminar_291118.pdf

    Malpedia library date fromORKL

  112. Analytics

    Malpedia library date Positive Technologies fromORKLCCS '25 data

  113. PKPLUG_ Chinese Cyber Espionage Group Attacking Asia

    date in the CCS '25 data Palo Alto fromORKLCCS '25 data

  114. PKPLUG- Chinese Cyber Espionage Group Attacking Asia

    date in the title fromORKL

  115. Into the Fog - The Return of ICEFOG APT

    Malpedia library date fromORKL

  116. mpressioncss_ta_report_2019.pdf

    Malpedia library date fromORKL

  117. Mustang Panda _ Threat Actor Profile _ CrowdStrike

    date in the CCS '25 data CrowdStrike fromORKLCCS '25 data

  118. BSides IR in Heterogeneous Environment

    Malpedia library date fromORKL

  119. security_report_20160613.pdf

    Malpedia library date fromORKL

  120. Uncovering the Seven Pointed Dagger

    Malpedia library date Arbor Networks fromORKLCCS '25 data

Newest first. Details opens the report in Explore.