Mustang Panda is a China-aligned cyber espionage threat actor known for sustained intelligence collection operations against government, diplomatic, military, education, telecommunications, energy, and policy-focused targets across Asia, Europe, and other regions. The group is widely tracked under numerous aliases including Earth Preta, Camaro Dragon, RedDelta, Bronze President, TA416, Hive0154, Stately Taurus, Twill Typhoon, Tantalum, TEMP.Hex, HoneyMyte, LuminousMoth, Cobalt Shadow, Fireant, and UNC6384. Reporting also associates related or overlapping subclusters and activity sets with names such as Red Lich and, in some contexts, Yokai-, Toneshell-, or PlugX-linked operations. The actor is characterized by long-running espionage campaigns that heavily rely on spearphishing, archive-based delivery, removable-media infection, and DLL sideloading through legitimate signed executables. Common tradecraft includes multi-stage loaders, shellcode execution via callback APIs, extensive API hashing and PEB walking, string obfuscation, staged decryption, scheduled-task or Run-key persistence, and use of legitimate cloud services to blend command-and-control and exfiltration traffic with normal enterprise activity. Mustang Panda has repeatedly used families and components associated with PlugX and Korplug, as well as newer tooling such as SHARDLOADER, MINIRECON, ZOHOMURK, ToneShell or TONESHELL variants, Pubload, Tonedisk, SnakeDisk, Yokai, LotusLite, and custom beacons structurally compatible with but distinct from public offensive frameworks. A defining feature of Mustang Panda operations is pragmatic adaptation of delivery and control channels. Campaigns have used DLL sideloading chains with decoy documents and signed software, malicious shortcut files, CHM extraction workflows, staged shellcode loaders, and counterfeit or trojanized removable media. The group has also abused trusted services for covert operations, including cloud storage and collaboration platforms. In 2026, the actor was observed using Zoho WorkDrive as a command-and-control and data exfiltration channel through the ZOHOMURK implant, while MINIRECON provided a TONESHELL-derived WebSocket-over-HTTPS backdoor with reverse-shell and file-transfer capability. Other observed tooling supports proxy-aware communications, fake TLS framing, DNS or UDP fallback, and modular plugin-based post-compromise functionality. Mustang Panda’s post-compromise behavior is consistent with mature espionage tradecraft. The group performs host and network reconnaissance, gathers system information, enumerates users and services, stages additional tools, and maintains stealth through masquerading, indicator removal, and use of legitimate binaries. Reported capabilities across its malware ecosystem include reverse shells, file upload and download, command execution, screenshot capture, keylogging, registry access, service control, process management, network share browsing, and selective persistence. Some variants include anti-analysis timing checks, certificate-validation bypass, polymorphic shellcode generation, and execution guards to reduce duplicate infections or hinder sandboxing. Geographically, Mustang Panda has been linked to campaigns targeting India, Vietnam, Thailand, Japan, Serbia and other European government entities, Australia, Myanmar-related diplomatic themes, and broader regional interests aligned with Chinese strategic priorities. Recent reporting highlights targeting of Indian government and hydropower organizations, likely for intelligence related to hydropower planning and India-Taiwan cooperation; Thailand-focused USB-propagating malware likely intended to penetrate segmented environments; and European government phishing operations using PlugX-associated tooling. The actor has also been associated with operations against government, education, and telecommunications sectors in Southeast Asia and Oceania. Attribution to China is supported by long-term operational patterns, malware lineage, infrastructure overlap, recurring development artifacts, and strong tradecraft continuity across campaigns. Public reporting frequently treats Hive0154, Earth Preta, Camaro Dragon, and Mustang Panda as overlapping or substantially related tracking designations for the same broader intrusion ecosystem, though some subclusters may represent distinct operational teams within that umbrella. Overall, Mustang Panda remains one of the most active and adaptable China-aligned espionage actors, notable for persistent tool evolution, extensive reuse of sideloading and PlugX-style tradecraft, and increasing abuse of legitimate cloud and removable-media channels to evade detection.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Geographies tied to known operations.
59 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
42 malware families attributed to this actor across reporting.
37 additional families tracked in Mallory.
6 CVEs this actor has used in observed campaigns. 6 of them exploited in the wild.
Microsoft has been aware of the flaw, tracked as CVE-2025-9491, at least since September 2024, when the Zero Day Initiative identified it as ZDI-25-148 and ZDI-CAN-25373 and notified Redmond. The vulnerability exists in how Windows processes .lnk files, which are desktop icons acting as a shortcut to another file or application.
...used exploits for... Word (CVE-2017-0199)...
Details on Exploited Vulnerabilities ... CVE-2021-1675 Microsoft Windows ... YARA Rules ... reference = “... PrintNightmare and MSHTML exploits” ... $cve1 = “CVE-2021-1675”
Details on Exploited Vulnerabilities ... CVE-2021-40444 Microsoft Windows ... YARA Rules ... reference = “... PrintNightmare and MSHTML exploits” ... $cve2 = “CVE-2021-40444”
Three Attack Variants Observed GrimResource (CVE-2025-26633): XSS via apds.dll res:// protocol handler
1 more CVE tied to this actor tracked in Mallory.
731 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Mentioned as a comparison point for similar signed-binary DLL sideloading tradecraft and PlugX delivery overlap.
Associated with a custom beacon shellcode/ToneShell sample delivered via SolidPDFCreator.dll side-loading in a campaign labeled “Target India 2026-05-28 Campaign 3.”
Conducting a multi-stage spear-phishing campaign targeting India, using a SolidPDFCreator.dll side-loading chain to deliver a ToneShell backdoor variant with WinHTTP WebSocket C2, reverse shell, file download, persistence, and obfuscation features.
Used multiple malware families and abused Zoho WorkDrive for command-and-control and data exfiltration.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.