Mustang Panda is a China-linked cyber-espionage threat actor known for sustained operations against government and other organizations across Asia and beyond. Widely tracked under aliases including HoneyMyte, RedDelta, Bronze President, Camaro Dragon, Cobalt Shadow, Earth Preta, Fireant, LuminousMoth, Stately Taurus, TA416, Tantalum, Twill Typhoon, and UNC6384, the group is associated with long-running intelligence collection campaigns and with targeting entities in countries such as Myanmar, Mongolia, Pakistan, Russia, Vietnam, India, Taiwan, Japan, South Korea, the United States, and others. The actor is known for using multi-stage intrusion chains, spearphishing and spam delivery, themed lures, DLL sideloading, malicious shortcut files, HTA and PowerShell-based execution, and abuse of legitimate signed executables to launch payloads. Mustang Panda has deployed malware families including PlugX and CoolClient, and has also used tooling such as Cobalt Strike and a Go-based loader. Recent activity shows an evolution of CoolClient into a more advanced espionage platform with a signed kernel-mode rootkit component that can conceal malicious processes, files, registry objects, kernel modules, and selected network information from user-mode inspection. In observed campaigns, PlugX has been used as an initial post-compromise implant before CoolClient is deployed as a secondary backdoor. Mustang Panda commonly establishes persistence through scheduled tasks, Run-key style autoruns, and Windows services. Observed tradecraft also includes privilege escalation via UAC bypass techniques, process injection, defense evasion through hidden files and directories, Microsoft Defender exclusion changes, and masquerading of malware components as legitimate software. The group performs extensive host and network reconnaissance, including process discovery, system information gathering, network configuration discovery, and Active Directory enumeration with AdFind. Collection behavior includes searching for common document formats and using capabilities such as keylogging, clipboard theft, credential harvesting, file management, and plugin-based backdoor extensions. The group’s operations are consistent with state-aligned intelligence objectives rather than financially motivated crime. Its targeting of government entities and regional geopolitical interests, together with repeated public reporting linking it to Chinese espionage activity, places Mustang Panda among the most active contemporary China-nexus intrusion sets.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
50 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
36 malware families attributed to this actor across reporting.
31 additional families tracked in Mallory.
6 CVEs this actor has used in observed campaigns. 6 of them exploited in the wild.
Microsoft has been aware of the flaw, tracked as CVE-2025-9491, at least since September 2024, when the Zero Day Initiative identified it as ZDI-25-148 and ZDI-CAN-25373 and notified Redmond. The vulnerability exists in how Windows processes .lnk files, which are desktop icons acting as a shortcut to another file or application.
...used exploits for... Word (CVE-2017-0199)...
Details on Exploited Vulnerabilities ... CVE-2021-1675 Microsoft Windows ... YARA Rules ... reference = “... PrintNightmare and MSHTML exploits” ... $cve1 = “CVE-2021-1675”
Details on Exploited Vulnerabilities ... CVE-2021-40444 Microsoft Windows ... YARA Rules ... reference = “... PrintNightmare and MSHTML exploits” ... $cve2 = “CVE-2021-40444”
Three Attack Variants Observed GrimResource (CVE-2025-26633): XSS via apds.dll res:// protocol handler
1 more CVE tied to this actor tracked in Mallory.
1,130 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Espionage intrusions deploying PlugX for initial foothold and CoolClient as a secondary backdoor, now enhanced with a signed kernel-mode rootkit/driver to hide processes, files, registry entries, and network activity.
Cyber-espionage operations involving an evolved CoolClient backdoor, with recent intrusions observed in late 2025 and 2026 targeting organizations in Asia and Russia, including campaigns against Pakistan, Mongolia, and Myanmar. In the Myanmar campaign, PlugX was used as an initial implant before deployment of CoolClient.
Conducting targeted espionage intrusions using the CoolClient backdoor, including a newer multi-stage Windows infection chain that abuses DLL sideloading and can deploy a signed kernel driver (msagent.sys) to hide or protect malware files, registry keys, and processes.
Deploying updated CoolClient backdoor variants with a signed kernel-mode rootkit for stealth and protection, using PlugX as an initial post-compromise implant and targeting government-linked victims.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.