Cyber threat actor
Mustang Panda
PRC state-sponsored · active since 2014
Targets NGOs, religious groups, ASEAN governments, and the Tibetan/Mongolian diaspora. Heavy use of PlugX delivered via USB and themed lures.
Aliases
BRONZE PRESIDENTRedDeltaEarth PretaTA416
Primary targets
ASEAN governments Vatican Tibetan diaspora European foreign ministries
MITRE ATT&CK techniques
4 techniques mapped · click any technique ID to open the MITRE ATT&CK entry, any CVE to view its NVD record, or any citation for source reporting.
| Tactic | Technique | Procedure | Targets | Citation |
|---|---|---|---|---|
| Initial Access | T1566.001 Spearphishing Attachment | Topical political lures (EU foreign policy, Ukraine, Tibet) delivering PlugX-laden archives. | EU foreign ministries, NGOs, Tibetan diaspora | Trend Micro Earth Preta |
| Initial Access | T1091 Replication Through Removable Media | USB-spreading PlugX variants (HIUPAN) targeting air-gapped or low-connectivity environments. | - | Trend Micro Earth Preta |
| Defense Evasion | T1574.002 DLL Side-Loading | Side-loaded malicious DLLs via legitimate signed binaries (Adobe, ESET, Avast) to evade EDR. | - | Trend Micro Earth Preta |
| Collection | T1119 Automated Collection (mobile) | Android spyware masquerading as Tibetan news/messaging apps for civil-society surveillance. | Tibetan diaspora (India, Nepal, Switzerland) | Citizen Lab |
Curated incidents
- 2024-10-05·Civil Society·India, Nepal, SwitzerlandCitizen Lab links Android spyware to Tibetan-diaspora monitoring
Sample masquerades as Tibetan news app; C2 overlaps MSS-aligned infrastructure.
- 2022-11-18·Diplomacy·EU member statesMustang Panda targets EU foreign ministries with Russia/Ukraine-themed lures
PlugX delivered via topical decoys, side-loaded via signed binaries.