MUSTANG PANDAMUSTANG PANDA

Also known as: MUSTANG PANDA · BRONZE PRESIDENT · HoneyMyte · Red Lich · TEMP.HEX · BASIN · Earth Preta · TA416 · Stately Taurus · LuminousMoth · Polaris · TANTALUM · Twill Typhoon

Known aliases
13

Profile

This threat actor targets nongovernmental organizations using Mongolian-themed lures for espionage purposes. In April 2017, CrowdStrike Falcon Intelligence observed a previously unattributed actor group with a Chinese nexus targeting a U.S.-based think tank. Further analysis revealed a wider campaign with unique tactics, techniques, and procedures (TTPs). This adversary targets non-governmental organizations (NGOs) in general, but uses Mongolian language decoys and themes, suggesting this actor has a specific focus on gathering intelligence on Mongolia. These campaigns involve the use of shared malware like Poison Ivy or PlugX. Recently, Falcon Intelligence observed new activity from MUSTANG PANDA, using a unique infection chain to target likely Mongolia-based victims. This newly observed activity uses a series of redirections and fileless, malicious implementations of legitimate tools to gain access to the targeted systems. Additionally, MUSTANG PANDA actors reused previously-observed legitimate domains to host files.

Aliases· 13

MUSTANG PANDABRONZE PRESIDENTHoneyMyteRed LichTEMP.HEXBASINEarth PretaTA416Stately TaurusLuminousMothPolarisTANTALUMTwill Typhoon

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

Actor
LOTUS PANDA
Actor
POISONUS PANDA
Actor
TEMPER PANDA
Actor
Vicious Panda
Actor
FOXY PANDA
Actor
Evasive Panda
Sourced from MISP-Galaxy Threat Actor cluster. Curated by Adam Lundqvist, Founder at SQUR.