← Threat Actors / China / MUSTANG PANDA
DOSSIER // MUSTANG-PANDA

MUSTANG PANDA

▲ High Threat China
Primary Aliases: DEV-0117 Mustang Panda Twill Typhoon UNC6384
Sponsor / State Affiliation China
Primary Motivation Espionage
Confidence Rating 70% (Grounded)

This threat actor targets nongovernmental organizations using Mongolian-themed lures for espionage purposes. In April 2017, CrowdStrike Falcon Intelligence observed a previously unattributed actor group with a Chinese nexus targeting a U.S.-based think tank. Further analysis revealed a wider campaign with unique tactics, techniques, and procedures (TTPs). This adversary targets non-governmental organizations (NGOs) in general, but uses Mongolian language decoys and themes, suggesting this actor has a specific focus on gathering intelligence on Mongolia. These campaigns involve the use of shared malware like Poison Ivy or PlugX. Recently, Falcon Intelligence observed new activity from MUSTANG PANDA, using a unique infection chain to target likely Mongolia-based victims. This newly observed activity uses a series of redirections and fileless, malicious implementations of legitimate tools to gain access to the targeted systems. Additionally, MUSTANG PANDA actors reused previously-observed legitimate domains to host files.

🎯 Target Sectors & Focus

Civil society

🛡️ MITRE ATT&CK® Attack Lifecycle (85 TTPs)

📥 Download Navigator JSON
Operational Techniques 50
T1000 Upload Malware
↗
T1000 Web Services
↗
T1000 Windows Management Instrumentation
↗
T1000 Symmetric Cryptography
↗
T1000 Search Open Websites/Domains
↗
T1000 Malicious Link
↗
T1000 Deobfuscate/Decode Files or Information
↗
T1000 Visual Basic
↗
T1000 IDE Tunneling
↗
T1000 Domain Account
↗
T1000 Hidden Files and Directories
↗
T1000 Mshta
↗
T1000 Dynamic API Resolution
↗
T1000 Email Accounts
↗
T1000 DCSync
↗
T1000 InstallUtil
↗
T1000 Archive via Utility
↗
T1000 Domain Groups
↗
T1000 Protocol or Service Impersonation
↗
T1000 Software Deployment Tools
↗
T1000 Adversary-in-the-Middle
↗
T1000 IDE Extensions
↗
T1000 Replication Through Removable Media
↗
T1000 LSASS Memory
↗
T1000 Tool
↗
T1000 Digital Certificates
↗
T1000 Archive via Custom Method
↗
T1000 File Deletion
↗
T1000 Shared Modules
↗
T1000 Non-Application Layer Protocol
↗
T1000 Executable Installer File Permissions Weakness
↗
T1000 Stage Capabilities
↗
T1000 Debugger Evasion
↗
T1000 Domains
↗
T1000 DLL
↗
T1000 Windows Management Instrumentation Event Subscription
↗
T1000 Native API
↗
T1000 NTDS
↗
T1000 Obfuscated Files or Information
↗
T1000 JavaScript
↗
T1000 Junk Code Insertion
↗
T1000 Malicious File
↗
T1000 Protocol Tunneling
↗
T1000 Masquerade File Type
↗
T1000 Double File Extension
↗
T1000 Web Service
↗
T1000 Traffic Signaling
↗
T1000 Match Legitimate Resource Name or Location
↗
T1000 Malware
↗
T1000 LNK Icon Smuggling
↗
Copied to clipboard

LINK COPIED TO CLIPBOARD