news.mlab.sh
Threat intelligence
Threat actor

Mustang Panda

Profile from actors.mlab.sh, coverage from our own index.

Suspected origin
China
First seen
2012-01-01 00:00:00
Motivation
Information theft and espionage
Targeted sectors
Aviation, Education, Government, Healthcare, NGOs, Think Tanks, Telecommunications
TLP
WHITE

(CrowdStrike) In April 2017, CrowdStrike Falcon Intelligence observed a previously unattributed actor group with a Chinese nexus targeting a U.S.-based think tank. Further analysis revealed a wider campaign with unique tactics, techniques, and procedures (TTPs). This adversary targets non-governmental organizations (NGOs) in general, but uses Mongolian language decoys and themes, suggesting this actor has a specific focus on gathering intelligence on Mongolia. These campaigns involve the use of shared malware like Poison Ivy or PlugX. Recently, Falcon Intelligence observed new activity from Mustang Panda, using a unique infection chain to target likely Mongolia-based victims. This newly observed activity uses a series of redirections and fileless, malicious implementations of legitimate tools to gain access to the targeted systems. Additionally, Mustang Panda actors reused previously-observed legitimate domains to host files. Also see CeranaKeeper and RedDelta.

Also known as

Bronze PresidentCamaro DragonClumsyToadEarth PretaFIREANTG0129Hive0154HoneyMyteLUMINOUS MOTHMustang PandaPKPLUGRed LichRedDeltaStately TaurusTA416TANTALUMTEMP.HexTwill TyphoonUNC6384

Vulnerabilities exploited

Tooling and malware

BOOKWORMCANONSTAGERChina ChopperCLAIMLOADERCobalt StrikeCorKLOGHIUPANPAKLOGPlugXPoisonIvyPUBLOADRCSessionShadowPadSplatCloakSplatDropperStarProxySTATICPLUGINTONESHELLAdFindImpacketMimikatzNBTscanWevtutil

MITRE ATT&CK techniques

T1119 Automated CollectionT1095 Non-Application Layer ProtocolT1102 Web ServiceT1105 Ingress Tool TransferT1572 Protocol TunnelingT1003 OS Credential DumpingT1557 Adversary-in-the-MiddleT1016 System Network Configuration DiscoveryT1018 Remote System DiscoveryT1046 Network Service DiscoveryT1049 System Network Connections DiscoveryT1057 Process DiscoveryT1082 System Information DiscoveryT1083 File and Directory DiscoveryT1518 Software DiscoveryT1654 Log EnumerationT1047 Windows Management InstrumentationT1059 Command and Scripting InterpreterT1072 Software Deployment ToolsT1106 Native APIT1129 Shared ModulesT1203 Exploitation for Client ExecutionT1041 Exfiltration Over C2 ChannelT1091 Replication Through Removable MediaT1593 Search Open Websites/DomainsT1608 Stage CapabilitiesT1027 Obfuscated Files or InformationT1070 Indicator RemovalT1140 Deobfuscate/Decode Files or InformationT1205 Traffic SignalingT1622 Debugger EvasionT1678 Delay Execution

Coverage 3