Mustang Panda, also tracked as Polaris, Hive0154, Stately Taurus, TA416, BRONZE PRESIDENT, and Earth Preta, is a China-linked advanced persistent threat focused primarily on cyber espionage. The group is known for sustained targeting of governments, diplomats, research organizations, and other public-sector entities, with a strong concentration on Taiwan and Southeast Asia, while also conducting operations affecting Europe and other regional neighbors of China. Reporting also links the actor to campaigns against Thai officials, Myanmar-related targets, attendees of defense-focused events, and Taiwanese government and diplomatic entities. The actor commonly relies on spear-phishing for initial access and has repeatedly used themed lures tied to current events and geopolitical developments, including early COVID-19-related collection activity. Mustang Panda is closely associated with a broad malware ecosystem centered on PlugX and its variants, as well as TONESHELL, PUBLOAD, DOPLUGS, Hodur, ShadowPad, MQsTTang, Yokai, and other loaders and backdoors. Public reporting also describes use of Cobalt Strike, credential-access tooling, remote administration utilities, and USB-propagating malware, reflecting an adaptable toolchain for intrusion, persistence, and post-compromise operations. Tradecraft attributed to Mustang Panda includes defense evasion through DLL sideloading and disguised command-and-control, including abuse of CDN and serverless infrastructure to conceal C2 traffic. The group has also been observed evolving malware families and delivery mechanisms over time, including custom PlugX development and newer backdoors tailored to regional espionage campaigns. Its operational pattern, victimology, and malware development are consistent with long-term intelligence collection in support of Chinese state interests.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
11 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 malware family attributed to this actor across reporting.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Mentioned as an example of a threat actor that has abused Cobalt Strike.
China-linked APT conducting spear-phishing against government and research institutes, likely to collect COVID-19-related intelligence.
Espionage tooling/arsenal discussed, including use of common post-exploitation frameworks and multiple backdoors.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.