created: 2026-09-24 · updated: 2026-09-24 · type: entity · tags: [apt-group, nation-state] · confidence: high · affected_sectors: [] · au_impact: false
Mustang Panda
Mustang Panda is a China-based cyber espionage threat actor that has been conducting operations since at least 2012. Mustang Panda has been known to use tailored phishing lures and decoy documents to deliver malicious payloads.
| Attribute | Detail |
|---|---|
| ATT&CK ID | G0129 |
| Aliases | TA416, RedDelta, BRONZE PRESIDENT, STATELY TAURUS, FIREANT, CAMARO DRAGON, EARTH PRETA, HIVE0154, TWILL TYPHOON, TANTALUM, LUMINOUS MOTH, UNC6384, TEMP.Hex, Red Lich, ClumsyToad |
| Attribution | China |
| Class | state |
| Active since | — |
| ATT&CK entry created | 2021-04-12 |
| Techniques mapped | 108 |
Attribution — as claimed
Stated by MITRE ATT&CK (state attribution).
Known TTPs
| Technique | Name |
|---|---|
T1001.003 |
Protocol or Service Impersonation |
T1003 |
OS Credential Dumping |
T1003.001 |
LSASS Memory |
T1003.003 |
NTDS |
T1003.006 |
DCSync |
T1016 |
System Network Configuration Discovery |
T1018 |
Remote System Discovery |
T1027 |
Obfuscated Files or Information |
T1027.007 |
Dynamic API Resolution |
T1027.012 |
LNK Icon Smuggling |
T1027.016 |
Junk Code Insertion |
T1036.005 |
Match Legitimate Resource Name or Location |
(First 12 of 108 ATT&CK-mapped techniques.)
Related Pages
- Mitre Attack — the framework this page's data is drawn from
- Ke3Chang — China-linked actor, same attribution class
- Earth Lusca — China-linked actor, same attribution class
- Salt Typhoon — China-linked actor, same attribution class
Provenance
Stub generated from MITRE ATT&CK G0129 on 2026-09-24. ATT&CK is the publisher of this page's technique and alias data; the attribution wording above is ATT&CK's, not this wiki's.