Cyber Threat Actor: Mustang Panda
| Actor Type | Location | Known Incidents |
Nation State
|
China
|
13 incidents |
|---|
Characteristics
Profile
Mustang Panda is a threat actor also known by the aliases Bronze President and HoneyMyte and is publicly linked to China as its presumed base of operations. Security researchers and multiple reporting sources have described the group as a Chinese state‑backed or nation‑state hacking entity, noting its alignment with broader Chinese cyber‑espionage efforts. The actor is characterized by a focus on intelligence gathering rather than financially motivated crime, with its activities described as espionage‑oriented campaigns against governmental, diplomatic and religious targets.
The group’s targeting patterns have been observed across several geographic regions and sectors, including Russian government officials in areas near the Chinese border, members of the Hong Kong Catholic Church involved in pro‑democracy activities, and Myanmar governmental entities such as the president’s office. Earlier activity has also been noted against European diplomats and various Myanmar‑based organizations, indicating a strategic interest in political and diplomatic entities that align with China’s regional interests. The actor’s objectives are consistently described as gathering intelligence and maintaining persistent access to networks of interest rather than seeking financial gain.
Mustang Panda’s tactical repertoire prominently features spear‑phishing campaigns that employ decoy documents designed to appear as legitimate files such as PDFs, Vatican communications, Catholic news articles or European Union sanction notices. These lures often contain malicious executables that employ DLL search order hijacking or DLL side‑loading techniques to load a malicious DLL, which in turn decrypts and executes the PlugX remote access trojan. The group frequently leverages legitimate, digitally signed files from trusted vendors—such as a Global Graphics Software Ltd file—to sidestep security controls, and it reuses infrastructure such as staging servers and domains previously linked to its operations, including the zyber‑i[.]com domain. In addition to phishing, the actor has used watering‑hole tactics, compromising websites to distribute malicious font packages that deliver backdoor trojans similar to earlier EvilGrab malware.
Notable publicly reported operations include a 2022‑04‑27 phishing campaign targeting Russian officials with EU sanction‑themed lures that deployed PlugX via DLL hijacking, a 2020‑05‑01 spear‑phishing effort against the Catholic Diocese of Hong Kong that used Vatican‑themed lures and DLL side‑loading to install PlugX, and a 2021‑06‑02 compromise of the Myanmar president’s website where a tampered font package served as a watering‑hole vector for a backdoor trojan linked to the group. Earlier intrusions against European diplomats and various Myanmar entities have been attributed to Mustang Panda based on reused infrastructure and malware characteristics, demonstrating a pattern of adapting lures while maintaining consistent tooling and command‑and‑control infrastructure. These activities collectively illustrate a persistent espionage focus that relies on social engineering, legitimate‑looking file abuse, and stealthy DLL‑based payload delivery.
