ChinaWidely attributedUnknownMITRE G0129

Mustang Panda

Mustang Panda is a China-based cyber espionage threat actor that has been conducting operations since at least 2012. Mustang Panda has been known to use tailored phishing lures and decoy documents to deliver malicious payloads. Mustang Panda has targeted government, diplomatic, and non-governmental organizations, including think tanks, religious institutions, and research entities, across the United States, Europe, and Asia, with notable activity in Russia, Mongolia, Myanmar, Pakistan, and Vietnam.

Attribution signal

?Score = mentions × confidence weight, summed across all attributed sources. Higher source diversity increases the score.≥ 10 High≥ 3 Moderate< 3 Low
2.8
Low signal strength
Mentions5
Sources2
High conf.2
Last seenMay 2026
First observed
2021-04-12
Last active
Origin
China
Aliases
17
Techniques
85
Campaigns
0
China

Attribution signals

5 mentions · 2 sources
#1mappedhigh
MalwareVictimology
checkpoint
May 2026

"Researchers mapped a Mustang Panda espionage campaign targeting India's banking sector and South Korean policy circles, deploying the updated LOTUSLITE backdoor."

Campaign: LOTUSLITE backdoor campaign
#2remainedhigh
Victimology
eset
May 2026

"Mustang Panda remained highly active in Southeast Asia, the United States, and Europe, focusing on the governmental, engineering, and maritime transport sectors."

#3China-alignedmoderate
Geopolitical
proofpoint
May 2026

"the China-aligned threat actor TA416 resumed observed targeting of European government and diplomatic organizations"

#4overlaps withmoderate
Unspecified
proofpoint
May 2026

"TA416 most directly overlaps with public reporting on RedDelta, Red Lich, Vertigo Panda, SmugX, and DarkPeony."

#5unspecifiedunspecified
MalwareTTP match
wechat-qax-ti
May 2026

"Mustang Panda (APT-C-08) organization recently uses Python samples packaged with NUITKA"

Hedge terms observed

China-alignedmappedoverlaps withremainedunspecified