Home · Wiki · Entities & Threat Actors
created: 2026-09-24 · updated: 2026-09-24 · type: entity · tags: [apt-group, nation-state] · confidence: high · affected_sectors: [] · au_impact: false

Mustang Panda

Mustang Panda is a China-based cyber espionage threat actor that has been conducting operations since at least 2012. Mustang Panda has been known to use tailored phishing lures and decoy documents to deliver malicious payloads.

Attribute Detail
ATT&CK ID G0129
Aliases TA416, RedDelta, BRONZE PRESIDENT, STATELY TAURUS, FIREANT, CAMARO DRAGON, EARTH PRETA, HIVE0154, TWILL TYPHOON, TANTALUM, LUMINOUS MOTH, UNC6384, TEMP.Hex, Red Lich, ClumsyToad
Attribution China
Class state
Active since
ATT&CK entry created 2021-04-12
Techniques mapped 108

Attribution — as claimed

Stated by MITRE ATT&CK (state attribution).

Known TTPs

Technique Name
T1001.003 Protocol or Service Impersonation
T1003 OS Credential Dumping
T1003.001 LSASS Memory
T1003.003 NTDS
T1003.006 DCSync
T1016 System Network Configuration Discovery
T1018 Remote System Discovery
T1027 Obfuscated Files or Information
T1027.007 Dynamic API Resolution
T1027.012 LNK Icon Smuggling
T1027.016 Junk Code Insertion
T1036.005 Match Legitimate Resource Name or Location

(First 12 of 108 ATT&CK-mapped techniques.)

Related Pages

  • Mitre Attack — the framework this page's data is drawn from
  • Ke3Chang — China-linked actor, same attribution class
  • Earth Lusca — China-linked actor, same attribution class
  • Salt Typhoon — China-linked actor, same attribution class

Provenance

Stub generated from MITRE ATT&CK G0129 on 2026-09-24. ATT&CK is the publisher of this page's technique and alias data; the attribution wording above is ATT&CK's, not this wiki's.