Skip to content
← All Threat Actors
Nation-State high China (PRC)

Mustang Panda

Chinese state-sponsored (MSS — Ministry of State Security) · Espionage / geopolitical intelligence / Southeast Asian and European foreign policy collection

Reports 1
Active Since 2012
Last Reported 24 Jun 2026
Sectors Targeted communications, critical-infrastructure, transport

Tactics, Techniques & Procedures (TTPs)

  • PlugX modular RAT deployed via DLL sideloading — the long-term persistence staple across a decade of operations
  • FDMTP backdoor (September 2025 – April 2026): fast-flux DNS TXT record C2 — infrastructure rotates faster than blocklists update
  • LOTUSLITE infostealer: automated credential extraction from Chrome, Firefox, and Edge with cloud credential harvesting
  • SnakeDisk USB worm: self-replicating infection of removable media to bridge air-gapped networks
  • DLL sideloading universal delivery pattern: legitimate signed binary sideloaded with malicious DLL across all campaigns
  • Spear-phishing with geopolitically resonant lures (South China Sea disputes, ASEAN documents, election materials, UN content)
  • Long-duration persistence — some compromises maintained for multiple years without detection

Known Targets

Southeast Asian government ministries (Myanmar, Laos, Cambodia, Vietnam, Thailand, Philippines)African government and NGO organisationsEuropean governments (expanded targeting from 2022)Religious organisations and NGOs in China-adjacent regionsUyghur community organisations (transnational repression mandate)

Analyst Notes

One of China's most prolific and persistent espionage APTs. Primarily serves MSS collection priorities across Southeast Asia, with significant Vatican/Catholic community targeting and transnational repression of Uyghur groups. European targeting expanded significantly post-2022, aligned with PRC foreign policy interest in European responses to the Ukraine conflict. A January 2025 Europol-coordinated operation disrupted PlugX-infected hosts globally, but operations continued with FDMTP fast-flux DNS C2 replacing PlugX in newer campaigns. The FDMTP rotation approach makes domain reputation blocking ineffective.

Also Known As

Twill Typhoon (Microsoft)Earth Preta (Trend Micro)Bronze President (Secureworks)TA416 (Proofpoint)RedDelta