Mustang Panda

APT / StateG0129
Origin🇨🇳 China
Techniques (MITRE ATT&CK)85
SourceMITRE ATT&CK
State sponsor: ChinaAttribution confidence: 50%Target categories: Civil society
Targeted regions: United States · Germany
Also known as:BASINBASIN CASTLEBRONZE PRESIDENTCAMARO DRAGONClumsyToadEARTH PRETAEarth PretaFIREANTHIVE0154HoneyMyteLUMINOUS MOTHLuminousMothPolarisRed LichRedDeltaSTATELY TAURUSStately TaurusTA416TANTALUMTEMP.HEXTEMP.HexTWILL TYPHOONTwill TyphoonUNC6384

Vexday analysis

Mustang Panda é um agente de espionagem cibernética de origem chinesa com operações documentadas desde pelo menos 2012, identificado no MITRE ATT&CK como G0129. O grupo é conhecido pelo uso de iscas de phishing direcionadas e documentos-isca para entrega de cargas maliciosas, tendo como alvos organizações governamentais, diplomáticas e não governamentais — incluindo think tanks, instituições religiosas e entidades de pesquisa — nos Estados Unidos, Europa e Ásia, com atividade notável na Rússia, Mongólia, Myanmar, Paquistão e Vietnã. Rastreado também pelos aliases TA416, RedDelta, BRONZE PRESIDENT, STATELY TAURUS, FIREANT e CAMARO DRAGON, o grupo acumula 85 técnicas documentadas no MITRE ATT&CK e tem uma CVE atribuída ao seu arsenal.

Attack chain

Plausible scenario built from the group's real techniques, ordered by the phases of an attack. Each step shows how the group typically operates.

Arsenal severity82
Impact: High
T1566.001T1047T1176.002T1546.003T1091T1074.001ENTRYInitial accessSpearphishingAttachmentEXECExecutionWindows ManagementInstrumentationPERSPersistenceIDE ExtensionsPRIVPrivilege escalationWindows ManagementInstrumentation E…LATLateral movementReplicationThrough Removable…COLLCollectionLocal Data StagingEXFILExfiltrationExfiltration OverC2 Channel

Illustrative chain derived from techniques documented in MITRE ATT&CK — it does not represent a specific past attack. Severity summarizes the known arsenal (kill-chain coverage, actively exploited CVEs, techniques).

Techniques (MITRE ATT&CK) 85

How the group operates, mapped to the MITRE ATT&CK matrix and organized by the phases of an attack.

defense-impairment

Exploited vulnerabilities 1

CVEs this group is known to exploit, per MITRE ATT&CK. Ordered by real-world severity.

Known infrastructure 1526

Real indicators (C2, domains, URLs and hashes) associated with the malware this group uses. Source: abuse.ch (ThreatFox, URLhaus, MalwareBazaar).

ip:port45.221.118.46:80Cobalt Strikethreatfox
ip:port45.221.118.46:443Cobalt Strikethreatfox
ip:port38.76.183.197:8082Cobalt Strikethreatfox
ip:port8.222.188.173:443Cobalt Strikethreatfox
ip:port8.219.220.240:7777Cobalt Strikethreatfox
ip:port209.99.184.234:50050Cobalt Strikethreatfox
ip:port120.77.42.217:50000Cobalt Strikethreatfox
ip:port49.235.52.47:3000Cobalt Strikethreatfox
ip:port49.235.52.47:8080Cobalt Strikethreatfox
ip:port49.235.52.47:80Cobalt Strikethreatfox
ip:port49.235.52.47:443Cobalt Strikethreatfox
ip:port49.235.52.47:8083Cobalt Strikethreatfox
ip:port147.139.136.105:8080Cobalt Strikethreatfox
ip:port38.207.177.165:8080Cobalt Strikethreatfox
ip:port147.139.136.105:80Cobalt Strikethreatfox
ip:port147.139.136.105:22Cobalt Strikethreatfox
ip:port147.139.136.105:443Cobalt Strikethreatfox
ip:port2.57.241.129:80Cobalt Strikethreatfox
ip:port38.207.177.165:80Cobalt Strikethreatfox
ip:port38.207.177.165:443Cobalt Strikethreatfox
ip:port147.139.245.149:801Cobalt Strikethreatfox
ip:port45.221.118.46:8080Cobalt Strikethreatfox
ip:port119.45.198.250:55555Cobalt Strikethreatfox
ip:port118.24.42.214:443Cobalt Strikethreatfox
ip:port47.251.29.219:50050Cobalt Strikethreatfox
ip:port47.254.68.68:50050Cobalt Strikethreatfox
ip:port172.232.97.189:4444Cobalt Strikethreatfox
ip:port149.88.66.234:21Cobalt Strikethreatfox
ip:port47.108.86.120:22Cobalt Strikethreatfox
ip:port47.108.86.120:111Cobalt Strikethreatfox

+1526 indicators in total. See them all on the IOCs page.

Mustang Panda uses real techniques and exploits real flaws. TrueHacking's AI Autonomous Pentest simulates these attacks against your infrastructure and brings more security to your application.

Explore the AI Autonomous Pentest →