← Threat Actors / China / MUSTANG PANDA
DOSSIER // MUSTANG-PANDA

MUSTANG PANDA

▲ High Threat China
Primary Aliases: DEV-0117 Twill Typhoon UNC6384 BASIN
Sponsor / State Affiliation China
Primary Motivation Espionage
Active Timeline Unknown – Present
Confidence Rating 70% (Grounded)

This threat actor targets nongovernmental organizations using Mongolian-themed lures for espionage purposes. In April 2017, CrowdStrike Falcon Intelligence observed a previously unattributed actor group with a Chinese nexus targeting a U.S.-based think tank. Further analysis revealed a wider campaign with unique tactics, techniques, and procedures (TTPs). This adversary targets non-governmental organizations (NGOs) in general, but uses Mongolian language decoys and themes, suggesting this actor has a specific focus on gathering intelligence on Mongolia. These campaigns involve the use of shared malware like Poison Ivy or PlugX. Recently, Falcon Intelligence observed new activity from MUSTANG PANDA, using a unique infection chain to target likely Mongolia-based victims. This newly observed activity uses a series of redirections and fileless, malicious implementations of legitimate tools to gain access to the targeted systems. Additionally, MUSTANG PANDA actors reused previously-observed legitimate domains to host files.

⚔️ Weaponized CVE Matrix (0)

No specific weaponized CVEs currently mapped in the public baseline.

🎯 Target Sectors & Focus

Civil society

🛡️ MITRE ATT&CK® Attack Lifecycle (85 TTPs)

📥 Download Navigator JSON
Operational Techniques 50
T1000 Upload Malware
T1000 Web Services
T1000 Windows Management Instrumentation
T1000 Symmetric Cryptography
T1000 Search Open Websites/Domains
T1000 Malicious Link
T1000 Deobfuscate/Decode Files or Information
T1000 Visual Basic
T1000 IDE Tunneling
T1000 Domain Account
T1000 Hidden Files and Directories
T1000 Mshta
T1000 Dynamic API Resolution
T1000 Email Accounts
T1000 DCSync
T1000 InstallUtil
T1000 Archive via Utility
T1000 Domain Groups
T1000 Protocol or Service Impersonation
T1000 Software Deployment Tools
T1000 Adversary-in-the-Middle
T1000 IDE Extensions
T1000 Replication Through Removable Media
T1000 LSASS Memory
T1000 Tool
T1000 Digital Certificates
T1000 Archive via Custom Method
T1000 File Deletion
T1000 Shared Modules
T1000 Non-Application Layer Protocol
T1000 Executable Installer File Permissions Weakness
T1000 Stage Capabilities
T1000 Debugger Evasion
T1000 Domains
T1000 DLL
T1000 Windows Management Instrumentation Event Subscription
T1000 Native API
T1000 NTDS
T1000 Obfuscated Files or Information
T1000 JavaScript
T1000 Junk Code Insertion
T1000 Malicious File
T1000 Protocol Tunneling
T1000 Masquerade File Type
T1000 Double File Extension
T1000 Web Service
T1000 Traffic Signaling
T1000 Match Legitimate Resource Name or Location
T1000 Malware
T1000 LNK Icon Smuggling
Copied to clipboard

LINK COPIED TO CLIPBOARD