Gold Open Source
ExplorePackagesVulnerabilitiesCWEsMCP ServersScan
Login
Gold Open Source

The authoritative source for production-ready open-source components. Every package, container image, AI model, and MCP server undergoes rigorous verification for security, malware, and license compliance.

Explore Gold

  • Explore Everything
  • Packages
  • Gold Certified Packages
  • Container Images
  • AI Models
  • MCP Servers
  • Agent Skills
  • Chip Manufacturers

Security Data & Tools

  • Scan Your Dependencies
  • Trending Threats
  • Threat RSS Feeds
  • CVE Database
  • Actively Exploited (KEV)
  • SGZ Zero-Days
  • CWE Index
  • MITRE ATT&CK
  • Malicious Packages
  • Security Glossary
  • Supply-Chain Report
  • Developers (API & Badge)
  • Chrome Extension
  • Credits & Data Sources

Products

  • The Platform
  • ESSCM
  • Portal
  • TPRM
  • OSM
  • Cowork
  • Code / Runner
  • Guard

Use Cases

  • Know Your Software
  • Auto-Fix Vulnerabilities
  • Asset Discovery
  • AI Governance
  • MCP Server Security
  • Supply Chain Compliance
  • Zero-Day Discovery
  • All Use Cases

Company

  • About
  • Pricing
  • Blog
  • Documentation
  • Safeguard Academy
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 Gold Open Source. All rights reserved.

Built with care bySafeguard
Home/ATT&CK/Groups/G0129
MITRE ATT&CK Group

Mustang Panda (G0129)

TA416RedDeltaBRONZE PRESIDENTSTATELY TAURUSFIREANTCAMARO DRAGONEARTH PRETAHIVE0154TWILL TYPHOONTANTALUMLUMINOUS MOTHUNC6384TEMP.HexRed LichClumsyToad
ShareXLinkedInRedditHN

[Mustang Panda](https://attack.mitre.org/groups/G0129) is a China-based cyber espionage threat actor that has been conducting operations since at least 2012. [Mustang Panda](https://attack.mitre.org/groups/G0129) has been known to use tailored phishing lures and decoy documents to deliver malicious payloads. [Mustang Panda](https://attack.mitre.org/groups/G0129) has targeted government, diplomatic, and non-governmental organizations, including think tanks, religious institutions, and research entities, across the United States, Europe, and Asia, with notable activity in Russia, Mongolia, Myanmar, Pakistan, and Vietnam. (Citation: BlackBerry MUSTANG PANDA October 2022)(Citation: Eset PlugX Korplug Mustang Panda March 2022)(Citation: Anomali MUSTANG PANDA October 2019)(Citation: Cisco Talos MUSTANG PANDA PLUGX PUBLOAD MAY 2022)(Citation: Secureworks BRONZE PRESIDENT December 2019)(Citation: DOJ Affidavit Search and Seizure PlugX December 2024)(Citation: EclecticIQ Mustang Panda PlugX)(Citation: ATTACKIQ MUSTANG PANDA TONESHELL March 2023)(Citation: Crowdstrike MUSTANG PANDA June 2018)(Citation: Palo Alto Networks, Unit 42)(Citation: Sophos PlugX September 2022)(Citation: Sophos Mustang Panda PLUGX)(Citation: Zscaler)

▪Techniques used (85)

T1016System Network Configuration DiscoveryT1608.001Upload MalwareT1583.006Web ServicesT1047Windows Management InstrumentationT1573.001Symmetric CryptographyT1593Search Open Websites/DomainsT1204.001Malicious LinkT1046Network Service DiscoveryT1140Deobfuscate/Decode Files or InformationT1049System Network Connections DiscoveryT1059.005Visual BasicT1219.001IDE TunnelingT1567.002Exfiltration to Cloud StorageT1053.005Scheduled TaskT1087.002Domain AccountT1598.003Spearphishing LinkT1678Delay ExecutionT1564.001Hidden Files and DirectoriesT1218.005MshtaT1027.007Dynamic API ResolutionT1585.002Email AccountsT1219.002Remote Desktop SoftwareT1218.004InstallUtilT1586.002Email AccountsT1560.001Archive via UtilityT1070Indicator RemovalT1071.001Web ProtocolsT1018Remote System DiscoveryT1069.002Domain GroupsT1001.003Protocol or Service ImpersonationT1048.003Exfiltration Over Unencrypted Non-C2 ProtocolT1566.002Spearphishing LinkT1041Exfiltration Over C2 ChannelT1072Software Deployment ToolsT1557Adversary-in-the-MiddleT1505.003Web ShellT1176.002IDE ExtensionsT1588.003Code Signing CertificatesT1091Replication Through Removable MediaT1059.003Windows Command ShellT1052.001Exfiltration over USBT1003.001LSASS MemoryT1588.002ToolT1588.004Digital CertificatesT1560.003Archive via Custom MethodT1070.004File DeletionT1129Shared ModulesT1057Process DiscoveryT1082System Information DiscoveryT1095Non-Application Layer ProtocolT1203Exploitation for Client ExecutionT1574.005Executable Installer File Permissions WeaknessT1608Stage CapabilitiesT1622Debugger EvasionT1566.001Spearphishing AttachmentT1654Log EnumerationT1083File and Directory DiscoveryT1518Software DiscoveryT1583.001DomainsT1574.001DLLT1546.003Windows Management Instrumentation Event SubscriptionT1106Native APIT1003.003NTDST1059Command and Scripting InterpreterT1553.002Code SigningT1027Obfuscated Files or InformationT1547.001Registry Run Keys / Startup FolderT1119Automated CollectionT1105Ingress Tool TransferT1074.001Local Data StagingT1059.007JavaScriptT1059.001PowerShellT1027.016Junk Code InsertionT1070.006TimestompT1204.002Malicious FileT1572Protocol TunnelingT1036.008Masquerade File TypeT1036.007Double File ExtensionT1102Web ServiceT1205Traffic SignalingT1036.005Match Legitimate Resource Name or LocationT1587.001MalwareT1027.012LNK Icon SmugglingT1003OS Credential DumpingT1003.006DCSync

▪Software used (23)

S1237CANONSTAGERmalwareS1238STATICPLUGINmalwareS0596ShadowPadmalwareS1239TONESHELLmalwareS0154Cobalt StrikemalwareS1230HIUPANmalwareS0357ImpackettoolS1234SplatCloakmalwareS1233PAKLOGmalwareS0645WevtutiltoolS0552AdFindtoolS1236CLAIMLOADERmalwareS0002MimikatztoolS1228PUBLOADmalwareS1227StarProxymalwareS1235CorKLOGmalwareS0662RCSessionmalwareS0590NBTscantoolS0012PoisonIvymalwareS1232SplatDroppermalwareS1226BOOKWORMmalwareS0020China ChoppermalwareS0013PlugXmalware
G0129on MITRE ATT&CK →

MITRE ATT&CK® is a registered trademark of The MITRE Corporation. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation.