Clankerusecase
Threat-actor profile
← Back to main site
Home/ Threat Actors/ Mustang Panda

🇨🇳Mustang Panda

🇨🇳 Mustang Panda is a tracked threat actor in the Clankerusecase corpus. Attributed to CN. Primary motivation: State. We map 26 detection use cases to this actor across 113 MITRE ATT&CK techniques, with 3 threat-intel articles citing them. Active in our corpus from 2025-11-06 to 2026-03-19.

crit 3
View full actor card → All threat actors MITRE ATT&CK group spec (G0129) ↗
26Use cases
3Articles
113Techniques
5IOCs

Known aliases

Mustang PandaTA416RedDeltaEarth PretaBronze PresidentStately TaurusBRONZE PRESIDENTSTATELY TAURUSFIREANTCAMARO DRAGONEARTH PRETAHIVE0154TWILL TYPHOONTANTALUMLUMINOUS MOTHUNC6384TEMP.HexRed LichClumsyToad

Top techniques

All other tracked techniques

T1001.003 · Protocol or Service ImpersonationT1003 · OS Credential DumpingT1003.001 · LSASS MemoryT1003.003 · NTDST1003.006 · DCSyncT1014 · RootkitT1016 · System Network Configuration DiscoveryT1018 · Remote System DiscoveryT1021.002 · SMB/Windows Admin SharesT1027 · Obfuscated Files or InformationT1027.002 · Software PackingT1027.005 · Indicator Removal from ToolsT1027.007 · Dynamic API ResolutionT1027.009 · Embedded PayloadsT1027.012 · LNK Icon SmugglingT1027.016 · Junk Code InsertionT1036.005 · Match Legitimate Resource Name or LocationT1036.007 · Double File ExtensionT1036.008 · Masquerade File TypeT1037.001 · Logon Script (Windows)T1041 · Exfiltration Over C2 ChannelT1046 · Network Service DiscoveryT1047 · Windows Management InstrumentationT1048.003 · Exfiltration Over Unencrypted Non-C2 ProtocolT1049 · System Network Connections DiscoveryT1052.001 · Exfiltration over USBT1053.005 · Scheduled TaskT1055 · Process InjectionT1057 · Process DiscoveryT1059 · Command and Scripting InterpreterT1059.001 · PowerShellT1059.003 · Windows Command ShellT1059.005 · Visual BasicT1059.007 · JavaScriptT1068 · Exploitation for Privilege EscalationT1069.002 · Domain GroupsT1070 · Indicator RemovalT1070.004 · File DeletionT1070.006 · TimestompT1071 · Application Layer ProtocolT1071.001 · Web ProtocolsT1072 · Software Deployment ToolsT1074.001 · Local Data StagingT1082 · System Information DiscoveryT1083 · File and Directory DiscoveryT1087.002 · Domain AccountT1091 · Replication Through Removable MediaT1095 · Non-Application Layer ProtocolT1102 · Web ServiceT1105 · Ingress Tool TransferT1106 · Native APIT1119 · Automated CollectionT1127.001 · MSBuildT1129 · Shared ModulesT1140 · Deobfuscate/Decode Files or InformationT1176.002 · IDE ExtensionsT1195.002 · Compromise Software Supply ChainT1203 · Exploitation for Client ExecutionT1204.001 · Malicious LinkT1204.004 · Malicious Copy and PasteT1205 · Traffic SignalingT1218 · System Binary Proxy ExecutionT1218.004 · InstallUtilT1218.005 · MshtaT1219 · Remote Access ToolsT1219.001 · IDE TunnelingT1219.002 · Remote Desktop SoftwareT1486 · Data Encrypted for ImpactT1489 · Service StopT1490 · Inhibit System RecoveryT1505.003 · Web ShellT1518 · Software DiscoveryT1543.003 · Windows ServiceT1546.003 · Windows Management Instrumentation Event SubscriptionT1547.001 · Registry Run Keys / Startup FolderT1553.002 · Code SigningT1555.003 · Credentials from Web BrowsersT1557 · Adversary-in-the-MiddleT1560.001 · Archive via UtilityT1560.003 · Archive via Custom MethodT1562.001 · T1562.001T1562.004 · T1562.004T1562.006 · T1562.006T1562.009 · T1562.009T1564.001 · Hidden Files and DirectoriesT1566.001 · Spearphishing AttachmentT1566.002 · Spearphishing LinkT1567.002 · Exfiltration to Cloud StorageT1569.002 · Service ExecutionT1572 · Protocol TunnelingT1573.001 · Symmetric CryptographyT1573.002 · Asymmetric CryptographyT1574.001 · DLLT1574.002 · T1574.002T1574.005 · Executable Installer File Permissions WeaknessT1583.001 · DomainsT1583.006 · Web ServicesT1585.002 · Email AccountsT1586.002 · Email AccountsT1587.001 · MalwareT1588.002 · ToolT1588.003 · Code Signing CertificatesT1588.004 · Digital CertificatesT1593 · Search Open Websites/DomainsT1598.003 · Spearphishing LinkT1608 · Stage CapabilitiesT1608.001 · Upload MalwareT1622 · Debugger EvasionT1654 · Log EnumerationT1678 · Delay Execution

Detection use cases (26)

Mustang Panda PlugX DLL side-loading via co-located signed loader in user-writable path AI · profile SΣDD Mustang Panda PlugX USB worm propagation (removable-drive LNK + hidden loader copy) AI · profile SDD BYOVD: Genshin Impact mhyprot.sys driver dropped/loaded outside legitimate game install (Embargo evil-mhyprot-cli) Bespoke EDRSilencer-style WFP filter blocking outbound traffic from named EDR binaries Bespoke EDR-Freeze: WerFaultSecure.exe abused to suspend AV/EDR processes via MiniDumpWriteDump race Bespoke Phishing-link click correlated to endpoint execution Internal Email attachment opened from external sender Internal Office app spawning script/LOLBin child process Internal Fake CAPTCHA / clipboard-injected PowerShell (ClickFix / FakeCaptcha) Internal PowerShell encoded / obfuscated command Internal Ransomware-style mass file rename / extension change Internal LSASS process access / dump (credential theft) Internal Remote service execution — PsExec / SMB lateral movement Internal Article-specific behavioural hunt — EDR killers explained: Beyond the drivers Internal Brand-Impersonation Domain Fetch Followed by User-Context Loader Within 10 Minutes MITRE match Cross-category credential-store enumeration with rapid egress to anonymizing tunnel/CDN MITRE match Cross-Platform ClickFix Paste-to-Pipe Loader (UI-Parent Shell with Decode-and-Execute Payload) MITRE match Developer package install spawning script-host with non-registry C2 within 5 minutes MITRE match Developer/Data-tooling Daemon Spawns Shell Child Seconds After POST to Runner/Exec Endpoint MITRE match Internet-Facing Service Process Spawning Unix Shell or Ingress-Tool LOLBin (Edge Zero-Day Post-Exploit) MITRE match Internet-facing service process spawns shell/LOLBin within minutes of public inbound connection — post-RCE command execution MITRE match Low-Code / AI Workflow Runtime Sandbox-Escape — Server Process Spawns Shell + Public Egress MITRE match Non-Browser Process Reads Browser Credential / Cookie SQLite Then Egresses to Public Destination Within 10 Minutes MITRE match npm/yarn/pnpm Install-Hook Spawn → Credential-Store Read or Worm-Payload Drop in node_modules MITRE match OAuth Device-Code Consent Phish to Cross-IP Cloud Token Replay MITRE match Package Manager / Dev-Tool Auto-Execution Triggers Non-Registry Egress or Credential-Store Access MITRE match

Threat-intel articles (3)

Tracked indicators

Domains (5)

decoorat.net decoraat.net gesecole.net onedow.gesecole.net onedown.gesecole.net

CVEs (2)

CVE-2024-42009 CVE-2025-8088