Threat intelligence
- Suspected origin
- China
- First seen
- 2012-01-01 00:00:00
- Motivation
- Information theft and espionage
- Targeted sectors
- Aviation, Education, Government, Healthcare, NGOs, Think Tanks, Telecommunications
- TLP
- WHITE
(CrowdStrike) In April 2017, CrowdStrike Falcon Intelligence observed a previously unattributed actor group with a Chinese nexus targeting a U.S.-based think tank. Further analysis revealed a wider campaign with unique tactics, techniques, and procedures (TTPs). This adversary targets non-governmental organizations (NGOs) in general, but uses Mongolian language decoys and themes, suggesting this actor has a specific focus on gathering intelligence on Mongolia. These campaigns involve the use of shared malware like Poison Ivy or PlugX.
Recently, Falcon Intelligence observed new activity from Mustang Panda, using a unique infection chain to target likely Mongolia-based victims. This newly observed activity uses a series of redirections and fileless, malicious implementations of legitimate tools to gain access to the targeted systems. Additionally, Mustang Panda actors reused previously-observed legitimate domains to host files.
Also see CeranaKeeper and RedDelta.
Also known as
Bronze PresidentCamaro DragonClumsyToadEarth PretaFIREANTG0129Hive0154HoneyMyteLUMINOUS MOTHMustang PandaPKPLUGRed LichRedDeltaStately TaurusTA416TANTALUMTEMP.HexTwill TyphoonUNC6384
Vulnerabilities exploited
Tooling and malware
BOOKWORMCANONSTAGERChina ChopperCLAIMLOADERCobalt StrikeCorKLOGHIUPANPAKLOGPlugXPoisonIvyPUBLOADRCSessionShadowPadSplatCloakSplatDropperStarProxySTATICPLUGINTONESHELLAdFindImpacketMimikatzNBTscanWevtutil
MITRE ATT&CK techniques
T1119 Automated CollectionT1095 Non-Application Layer ProtocolT1102 Web ServiceT1105 Ingress Tool TransferT1572 Protocol TunnelingT1003 OS Credential DumpingT1557 Adversary-in-the-MiddleT1016 System Network Configuration DiscoveryT1018 Remote System DiscoveryT1046 Network Service DiscoveryT1049 System Network Connections DiscoveryT1057 Process DiscoveryT1082 System Information DiscoveryT1083 File and Directory DiscoveryT1518 Software DiscoveryT1654 Log EnumerationT1047 Windows Management InstrumentationT1059 Command and Scripting InterpreterT1072 Software Deployment ToolsT1106 Native APIT1129 Shared ModulesT1203 Exploitation for Client ExecutionT1041 Exfiltration Over C2 ChannelT1091 Replication Through Removable MediaT1593 Search Open Websites/DomainsT1608 Stage CapabilitiesT1027 Obfuscated Files or InformationT1070 Indicator RemovalT1140 Deobfuscate/Decode Files or InformationT1205 Traffic SignalingT1622 Debugger EvasionT1678 Delay Execution
Coverage 3
threat-intel
A cyber espionage campaign, dubbed Operation QUICSILVER, targeting Myanmar's government and IT sector is being conducted by a China-linked threat actor. The campaign uses a graduation ceremony lure to deliver a Go backdo…

threat-intel
The HoneyMyte threat actor (aka Mustang Panda) has updated its CoolClient backdoor with a new, signed Windows kernel-mode rootkit, significantly enhancing its stealth capabilities. This rootkit, implemented through a dri…

threat-intel
A long-standing supply chain attack targeting QuickFox, a VPN tool used by overseas Chinese users, has been ongoing since August 2025. The attack, attributed to tactical overlaps with the Chinese state-sponsored threat a…
