Overview 540 indicators
Mustang Panda is a China-based cyber espionage threat actor that has been conducting operations since at least 2012. Mustang Panda has been known to use tailored phishing lures and decoy documents to deliver malicious payloads. Mustang Panda has targeted government, diplomatic, and non-governmental organizations, including think tanks, religious institutions, and research entities, across the United States, Europe, and Asia, with notable activity in Russia, Mongolia, Myanmar, Pakistan, and Vietnam.
| domain | 319 | G0129-domain.txt |
| ipv4 | 149 | G0129.json |
| url | 53 | G0129.json |
| url_path | 19 | G0129.json |
Techniques 85 ATT&CK
Open in ATT&CK Navigator → or download the layer (85 techniques, layer 4.5)
- T1001.003 Protocol or Service Impersonation
- T1003 OS Credential Dumping
- T1003.001 LSASS Memory
- T1003.003 NTDS
- T1003.006 DCSync
- T1016 System Network Configuration Discovery
- T1018 Remote System Discovery
- T1027 Obfuscated Files or Information
- T1027.007 Dynamic API Resolution
- T1027.012 LNK Icon Smuggling
- T1027.016 Junk Code Insertion
- T1036.005 Match Legitimate Resource Name or Location
- T1036.007 Double File Extension
- T1036.008 Masquerade File Type
- T1041 Exfiltration Over C2 Channel
- T1046 Network Service Discovery
- T1047 Windows Management Instrumentation
- T1048.003 Exfiltration Over Unencrypted Non-C2 Protocol
- T1049 System Network Connections Discovery
- T1052.001 Exfiltration over USB
- T1053.005 Scheduled Task
- T1057 Process Discovery
- T1059 Command and Scripting Interpreter
- T1059.001 PowerShell
- T1059.003 Windows Command Shell
- T1059.005 Visual Basic
- T1059.007 JavaScript
- T1069.002 Domain Groups
- T1070 Indicator Removal
- T1070.004 File Deletion
- T1070.006 Timestomp
- T1071.001 Web Protocols
- T1072 Software Deployment Tools
- T1074.001 Local Data Staging
- T1082 System Information Discovery
- T1083 File and Directory Discovery
- T1087.002 Domain Account
- T1091 Replication Through Removable Media
- T1095 Non-Application Layer Protocol
- T1102 Web Service
- T1105 Ingress Tool Transfer
- T1106 Native API
- T1119 Automated Collection
- T1129 Shared Modules
- T1140 Deobfuscate/Decode Files or Information
- T1176.002 IDE Extensions
- T1203 Exploitation for Client Execution
- T1204.001 Malicious Link
- T1204.002 Malicious File
- T1205 Traffic Signaling
- T1218.004 InstallUtil
- T1218.005 Mshta
- T1219.001 IDE Tunneling
- T1219.002 Remote Desktop Software
- T1505.003 Web Shell
- T1518 Software Discovery
- T1546.003 Windows Management Instrumentation Event Subscription
- T1547.001 Registry Run Keys / Startup Folder
- T1553.002 Code Signing
- T1557 Adversary-in-the-Middle
- T1560.001 Archive via Utility
- T1560.003 Archive via Custom Method
- T1564.001 Hidden Files and Directories
- T1566.001 Spearphishing Attachment
- T1566.002 Spearphishing Link
- T1567.002 Exfiltration to Cloud Storage
- T1572 Protocol Tunneling
- T1573.001 Symmetric Cryptography
- T1574.001 DLL
- T1574.005 Executable Installer File Permissions Weakness
- T1583.001 Domains
- T1583.006 Web Services
- T1585.002 Email Accounts
- T1586.002 Email Accounts
- T1587.001 Malware
- T1588.002 Tool
- T1588.003 Code Signing Certificates
- T1588.004 Digital Certificates
- T1593 Search Open Websites/Domains
- T1598.003 Spearphishing Link
- T1608 Stage Capabilities
- T1608.001 Upload Malware
- T1622 Debugger Evasion
- T1654 Log Enumeration
- T1678 Delay Execution
Software 23
- Mimikatz
- PoisonIvy
- PlugX
- China Chopper
- Cobalt Strike
- Impacket
- AdFind
- NBTscan
- ShadowPad
- Wevtutil
- RCSession
- BOOKWORM
- StarProxy
- PUBLOAD
- HIUPAN
- SplatDropper
- PAKLOG
- SplatCloak
- CorKLOG
- CLAIMLOADER
- CANONSTAGER
- STATICPLUGIN
- TONESHELL
Principal sources 205 reports
Ranked by how many of this actor's indicators each report brought in.
- 79x.com/Cyberteam008/status/1914501911241228629
- 70x.com/askardyuss/status/2069389179440816153
- 70virustotal.com/gui/file/b7f692ae4d4ebfa82109bd74475c79…
- 35validin.com/blog/hunting_pandas
- 35x.com/Thisism23567356/status/1904855651936776…
- 35app.validin.com/detail?find=b9dceb7aa7369a63f1c64648a3b…
- 20mcafee.com/enterprise/en-us/assets/reports/rp-oper…
- 20otx.alienvault.com/pulse/6050e65d389812e02dfca3c3
Related groups 6
What the sources have in common — not a claim that these are the same actor. See the whole graph.
Timeline 540 indicators
Each entry is a batch of indicators that appeared upstream on one date, under the report it was filed with.
Showing the 300 most recent of 540. Complete: G0129.json.
No indicator matches. Only the most recent 300 are on this page — the rest are in the JSON.
-
x.com/Cyberteam008/status/2074340012288844049
102.211.234.105:443 103.175.50.32:443 103.245.164.154:443 103.247.19.204:443 146.70.29.241:443 154.196.139.38:443 176.97.117.5:443 185.9.17.213:443 188.208.141.177:443 194.5.97.169:443 194.59.183.133:443 195.66.213.170:443 2.59.216.250:443 38.54.42.106:443 45.89.105.83:443 -
acronis.com/en/tru/posts/mustang-panda-targets-indi…
domain couldinstallup.com domain kuhkhjvmjh.com domain syncnovaall.com domain thesiamworks.com ipv4 188.208.141.177:47001 -
x.com/SinghSoodeep/status/1974780785782837632 · proofpoint.com/us/blog/threat-insight/id-come-running-…
mydownload.z29.web.core.windows.net -
proofpoint.com/us/blog/threat-insight/id-come-running-…
attd.z23.web.core.windows.net -
arcticwolf.com/resources/blog/unc6384-weaponizes-zdi-c… · proofpoint.com/us/blog/threat-insight/id-come-running-…
mydownloadfile.z7.web.core.windows.net -
x.com/askardyuss/status/2069389179440816153 · virustotal.com/gui/file/b7f692ae4d4ebfa82109bd74475c79…
21-ninety.com 3012965.securefastserver.com 3784f20bb00.com 9521182.com b83928922.questincc.com babyafrosapparel.com backups.muathye.com c7p949983.silveradeearyray.com calendargbmechanical.cam calendarthomastecs.cam calendercongress.cam calendercongress.com concreteinportland.com connectmvasalu.cam constructionferryfences.cam drive.babyafrosapparel.com ferryfences.cam ferryfencesconstruc.cam ferryfencesconstruction.cam fil76v6shar604bbdoc0o.com fileclub.modaestilo.net files.riddhiman.shop fileshare.babyafrosapparel.com fileshare.gorollerskate.com filevault.soundit.co gorollerskate.com hb3788263.questincc.com holtconstruction.cam holtlogistics.cam hydrationroom.cam jk319201923.lectrosonic.com kantolocalfinance.com lectrosonic.com lm663772881.questincc.com mail.kantolocalfinance.com mail.nexushighcargo.com mail.oceancertsurveyors.com meet.schedulethomastecs.cam modaestilo.net myfile.tokyobighub.com next.calendarthomastecs.cam next.connectmvasalu.cam next.schedulethomastecs.cam next.schthomastecs.cam nexthomastecs.cam nexushighcargo.com nx39489933.ltapprel.com oceancertsurveyors.com offerbox.pro pass.romexperts.com pumpamed.com qlv838393942.watchefswant.com resources.babyafrosapparel.com riddhiman.shop romexperts.com rt47588343.lectrosonic.com schedule.thomastecs.cam scheduleferryfences.cam schedulethomastecs.cam schthomastecs.cam secondomoma.com silveradeearyray.com stlfast.com thomastecs.cam tokyobighub.com update.babyafrosapparel.com vie3490gy23777bnufil8903456bil623000r789sit986uhhh.com viksend.vikkify.com widgets.babyafrosapparel.com yg7488392.lectrosonic.com -
darktrace.com/blog/chinese-apt-campaign-targets-entit…
domain icloud-cdn.net domain yahoo-cdn.it.com ipv4 154.223.58.142:20807 ipv4 154.223.58.142:20811 -
acronis.com/en/tru/posts/same-packet-different-magi… · virustotal.com/gui/file/18bc0e0f627d90fb283aa243055b46…
domain editor.gleeze.com ipv4 103.79.77.181:443 url cosmosmusic.com/upload/pds/_notes/music.js -
x.com/G60930953/status/2008641011514585094 · x.com/AzakaSekai_/status/2009481951368135097 · acronis.com/en/tru/posts/lotuslite-targeted-espiona… · virustotal.com/gui/file/231bac4015da9157553f5a8090bea3… · virustotal.com/gui/file/2c34b47ee7d271326cfff970137727…
unassigned.172-81-60-97.spryt.net -
proofpoint.com/us/blog/threat-insight/id-come-running-…
filesdownld.z13.web.core.windows.net filestoretome.z23.web.core.windows.net gooledives.z48.web.core.windows.net reloadsite.z13.web.core.windows.net -
x.com/goldenjackel12/status/20265292787589901… · x.com/malwrhunterteam/status/2026614706866180… · virustotal.com/gui/file/30c71d644bc72e0d55d46bed753ab3… · virustotal.com/gui/file/e79d19d68d307c12413f8549aafa4a…
devlyrics.com devlyrics.github.io -
x.com/G60930953/status/2008641011514585094 · x.com/AzakaSekai_/status/2009481951368135097 · acronis.com/en/tru/posts/lotuslite-targeted-espiona… · virustotal.com/gui/file/231bac4015da9157553f5a8090bea3… · virustotal.com/gui/file/2c34b47ee7d271326cfff970137727…
172.81.60.97:3389 172.81.60.97:443 -
x.com/Cyberteam008/status/1914501911241228629
aadcdn.msauth.document-invoiceviewer.online aadcdn.msauth.document-viewer.xyz aadcdn.msauth.documentpdfviewer.xyz account.live.document-invoiceviewer.online account.live.document-viewer.xyz account.live.office-docs.online accounts.documentpdfviewer.xyz accounts.hmailevma5.documentpdfviewer.xyz api.document-invoiceviewer.online api.document-viewer.xyz api.office-docs.online b.document-viewer.xyz csp.document-invoiceviewer.online csp.document-viewer.xyz csp.documentpdfviewer.xyz csp.office-docs.online document-invoiceviewer.online document-viewer.xyz documentinvoice-viewer.top documentpdfviewer.xyz events.api.document-invoiceviewer.online events.api.document-viewer.xyz events.api.office-docs.online files.document-invoiceviewer.online files.document-viewer.xyz files.documentpdfviewer.xyz files.office-docs.online files.office3-docviewer.com flowise.document-viewer.xyz gui.document-invoiceviewer.online gui.documentpdfviewer.xyz gui.office-docs.online hmailevma5.documentpdfviewer.xyz img1.document-invoiceviewer.online img1.documentpdfviewer.xyz img1.office-docs.online img6.document-invoiceviewer.online img6.document-viewer.xyz img6.documentpdfviewer.xyz img6.office-docs.online live.document-invoiceviewer.online live.document-viewer.xyz live.documentpdfviewer.xyz live.office-docs.online login-us.document-viewer.xyz login.document-invoiceviewer.online login.document-viewer.xyz login.documentpdfviewer.xyz login.live.document-invoiceviewer.online login.live.documentpdfviewer.xyz login.live.office-docs.online login.office-docs.online logincdn.document-invoiceviewer.online logincdn.documentpdfviewer.xyz logincdn.office-docs.online m365.office-docs.online msauth.document-invoiceviewer.online msauth.document-viewer.xyz msauth.documentpdfviewer.xyz myaccount.documentpdfviewer.xyz myaccount.hmailevma5.documentpdfviewer.xyz myanmarclouddrive.ru office-docs.online office.document-invoiceviewer.online office.document-viewer.xyz office.documentpdfviewer.xyz office.office-docs.online office3-docviewer.com pdf.document-viewer.xyz pdf.documentpdfviewer.xyz portal.document-invoiceviewer.online portal.document-viewer.xyz portal.office-docs.online qa.flowise.document-viewer.xyz sajjadsmziranir.iransmz.tech share.office-docs.online smz4.iransmz.tech sso.document-invoiceviewer.online webmail.documentpdfviewer.xyz -
validin.com/blog/hunting_pandas · x.com/Thisism23567356/status/1904855651936776… · app.validin.com/detail?find=b9dceb7aa7369a63f1c64648a3b…
domain gclm.name domain haberciinternational.com domain jpkinki.com domain renxinguo.com ipv4 103.107.104.61:443 ipv4 103.107.104.61:8088 ipv4 103.79.120.70:443 ipv4 103.79.120.70:8088 ipv4 103.79.120.71:443 ipv4 103.79.120.71:8088 ipv4 103.79.120.73:443 ipv4 103.79.120.73:8088 ipv4 103.79.120.74:443 ipv4 103.79.120.74:8088 ipv4 103.79.120.81:443 ipv4 103.79.120.81:8088 ipv4 103.79.120.85:443 ipv4 103.79.120.89:443 ipv4 136.0.141.189:443 ipv4 136.0.141.189:5000 ipv4 136.0.141.189:8088 ipv4 139.180.192.163:443 ipv4 139.180.192.163:8088 ipv4 173.199.71.152:443 ipv4 173.199.71.152:8443 ipv4 223.26.52.245:443 ipv4 223.26.52.245:5000 ipv4 223.26.52.245:8090 ipv4 38.89.72.133:443 ipv4 45.152.65.213:443 ipv4 45.195.69.111:443 ipv4 45.195.69.111:5000 ipv4 45.195.69.111:8088 ipv4 83.229.127.115:443 ipv4 83.229.127.115:5000 -
ti.qianxin.com/blog/articles/operation-sea-elephant-th… · mp.weixin.qq.com/s?__biz=MzI2MDc2MDA4OA==&mid=2247514297…
domain aliyunconsole.com ipv4 185.140.12.224:443 ipv4 185.243.112.79:52736 ipv4 192.52.166.252:443 ipv4 2.58.15.28:8090 ipv4 45.86.162.125:52736 ipv4 45.86.162.79:443 ipv4 66.85.26.161:443 url_path /cgyusdft/ url_path /cgyusdft/whfgujfg/ url_path /csgdyhfywhefdj/ url_path /csgdyhfywhefdj/gdydfhasc/ url_path /gdydfhasc/ url_path /whfgujfg/ -
zscaler.com/blogs/security-research/latest-mustang-… · virustotal.com/gui/ip-address/181.215.246.155/relations · virustotal.com/gui/file/0d0296e94f6117ac0852b5c11a4cab…
domain dest-working.com domain profile-keybord.com ipv4 103.13.31.75:443 ipv4 43.229.79.163:443 ipv4 43.254.132.217:443 url http://103.13.31.75 url_path /heugojhgriuhn78867jhkbjkdgfhuie78/ url_path /heugojhgriuhn78867jhkbjkdgfhuie78/jhegiokj7889seghjegh786jkhegfukj/ url_path /jhegiokj7889seghjegh786jkhegfukj/ -
unit42.paloaltonetworks.com/stately-taurus-uses-bookworm-malware
b8pjmgd6.com fjke5oe.com ggrdl4.com gm4rys.com hbsanews.com i5y3dl.com update.fjke5oe.com zimbra.page -
x.com/felixaime/status/1674724194976776194
107.155.56.87:53 152.32.130.139:443 152.32.130.139:5000 86.0.0.13:8080 -
ibm.com/think/x-force/hive0154-drops-updated-to… · virustotal.com/gui/file/564a03763879aaed4da8a8c1d6067f… · virustotal.com/gui/file/c6e2d561b20fa38f79a28350cb397a…
domain sclickvpn.com ipv4 146.70.29.229:443 url http://118.174.183.89 url_path /kptinfo/import/index.php -
x.com/Cyberteam008/status/1901817451274539274 · virustotal.com/gui/file/080386f5dc89d42d7c1e684ca371b5…
103.56.18.101:443 103.56.18.101:53 -
arcticwolf.com/resources/blog/unc6384-weaponizes-zdi-c…
d32tpl7xt7175h.cloudfront.net mydownfile.z11.web.core.windows.net -
cloud.google.com/blog/topics/threat-intelligence/prc-nex…
domain mediareleaseupdates.com ipv4 166.88.2.90:443 -
ibm.com/think/x-force/hive0154-mustang-panda-sh… · virustotal.com/gui/file/d99e33878e23582308b1e217aff4a5… · virustotal.com/gui/file/98c1527d4b064fcf4a95488c34576e… · virustotal.com/gui/file/9335e9ec308de135651bec4b3f2f4f… · virustotal.com/gui/file/6e408aada775eaf19c524792344cab…
218.255.96.245:443 -
twitter.com/k3yp0d/status/1683811748871122944 · go.recordedfuture.com/hubfs/reports/cta-cn-2025-0109.pdf · virustotal.com/gui/file/a0a3eeb6973f12fe61e6e90fe5fe8e… · virustotal.com/gui/file/471e61015ff18349f4bf357447597a…
tasensors.com -
x.com/smica83/status/1870033683547111614 · x.com/frdfzi/status/1870018996717924829 · virustotal.com/gui/file/5b18f8b379cb32945ef7722b7ec175… · virustotal.com/gui/file/62087a1226c5433d6f6184d627c487…
ipv4 185.62.57.118:443 ipv4 45.144.165.66:443 url http://185.62.57.118 url http://45.144.165.66 -
x.com/Thisism23567356/status/1863490595550883… · virustotal.com/gui/file/065585a379615b6bec23d1c9c41454…
domain srv1.blackberrygame.com ipv4 146.70.149.186:443 -
x.com/Thisism23567356/status/1858518325346574…
openai-cheapagent.com -
x.com/frdfzi/status/1858524001947279652 · virustotal.com/gui/ip-address/188.208.141.218/relations · virustotal.com/gui/file/035d1f670b5e9d29d65fbb2b309ae0…
formainservercheap.com preperlanguageserver.com -
x.com/frdfzi/status/1849616996222349674 · virustotal.com/gui/file/f00e5ff2dc47a7625c86ac89784d5a…
lyjxq3.com -
x.com/ESETresearch/status/1841466248367915019 · x.com/ESETresearch/status/1841466250469261374 · welivesecurity.com/en/eset-research/separating-bee-panda-c… · github.com/eset/malware-ioc/tree/master/ceranakeep… · virustotal.com/gui/ip-address/103.245.165.237/relations · virustotal.com/gui/ip-address/103.27.202.185/relations · virustotal.com/gui/file/b25c79ba507a256c9ca12a9bd34def… · virustotal.com/gui/file/dafad19900fff383c2790e017c958a… · virustotal.com/gui/file/451ee465675e674cebe3c42ed41356… · virustotal.com/gui/file/6655c5686b9b0292cf5121fc634634…
dl6yfsl.com dljmp2p.com inly5sf.com toptipvideo.com -
x.com/felixaime/status/1674724194976776194
107.155.56.87:443 -
x.com/VirITeXplorer/status/1829426003103363123 · x.com/Thisism23567356/status/1834216409787674… · virustotal.com/gui/file/79d3481bac60ac1ecc7e2d1a4b86bd… · virustotal.com/gui/file/0b152012c1deab39c6ed7fe75a2716… · virustotal.com/gui/file/00619a5312d6957248bac777c44c0e…
conflictaslesson.com goclamdep.net lokjopppkuimlpo.shop -
trendmicro.com/en_us/research/24/i/earth-preta-new-mal… · trendmicro.com/content/dam/trendmicro/global/en/resear…
domain aihkstore.com domain bcller.com domain ynsins.com ipv4 103.15.29.17:443 ipv4 154.90.32.88:443 ipv4 18.163.112.181:443 ipv4 47.253.106.177:443 ipv4 47.76.87.55:443 -
x.com/VirITeXplorer/status/1829426003103363123 · x.com/Thisism23567356/status/1834216409787674… · virustotal.com/gui/file/79d3481bac60ac1ecc7e2d1a4b86bd… · virustotal.com/gui/file/0b152012c1deab39c6ed7fe75a2716… · virustotal.com/gui/file/00619a5312d6957248bac777c44c0e…
domain kxmmcdmnb.online url_path /eciwrnjnx url_path /eufzyzhd url_path /kjuehbit
Further reading 223
- attack.mitre.org/groups/G0129
- blog.cloudflare.com/2026-threat-report
- blog.eclecticiq.com/mustang-panda-apt-group-uses-european-c…
- blog.talosintelligence.com/mustang-panda-targets-europe
- blogs.blackberry.com/en/2022/10/mustang-panda-abuses-legitim…
- cloud.google.com/blog/topics/threat-intelligence/prc-nex…
- csirt-cti.net/2024/01/23/stately-taurus-targets-myanm…
- go.recordedfuture.com/hubfs/reports/cta-2020-0728.pdf
- learn.microsoft.com/en-us/unified-secops-platform/microsoft…
- research.checkpoint.com/2023/the-dragon-who-sold-his-camaro-ana…
- unit42.paloaltonetworks.com/bookworm-trojan-a-model-of-modular-arch…
- unit42.paloaltonetworks.com/stately-taurus-abuses-vscode-southeast-…
- unit42.paloaltonetworks.com/stately-taurus-attacks-se-asian-governm…
- unit42.paloaltonetworks.com/stately-taurus-uses-bookworm-malware
- anomali.com/blog/china-based-apt-mustang-panda-targ…
- attackiq.com/2023/03/23/emulating-the-politically-mo…
- broadcom.com/support/security-center/protection-bull…
- crowdstrike.com/blog/meet-crowdstrikes-adversary-of-the…
- ibm.com/think/x-force/hive0154-mustang-panda-sh…
- ibm.com/think/x-force/hive0154-targeting-us-phi…
- justice.gov/archives/opa/media/1384136/dl
- proofpoint.com/us/blog/threat-insight/good-bad-and-web…
- proofpoint.com/us/blog/threat-insight/ta416-goes-groun…
- pwc.co.uk/cyber-security/pdf/pwc-cyber-threats-20…
- secureworks.com/blog/bronze-president-targets-governmen…
- otx.alienvault.com/pulse/6144875da41b403380a06521
- virustotal.com/gui/file/47eb43acdd342d3975000f650cf656…
- virustotal.com/gui/file/51d89afe0a49a3abf88ed6f032e4f0…
- x.com/Thisism23567356/status/1834216409787674…
- virustotal.com/gui/file/6e408aada775eaf19c524792344cab…
- trendmicro.com/en_us/research/24/b/earth-preta-campaig…
- virustotal.com/gui/file/451ee465675e674cebe3c42ed41356…
- virustotal.com/gui/file/c6e2d561b20fa38f79a28350cb397a…
- x.com/frdfzi/status/1849616996222349674
- go.recordedfuture.com/hubfs/reports/cta-cn-2025-0109.pdf
- cloud.google.com/blog/topics/threat-intelligence/prc-nex…
- virustotal.com/gui/file/d99e33878e23582308b1e217aff4a5…
- virustotal.com/gui/file/a0a3eeb6973f12fe61e6e90fe5fe8e…
- twitter.com/hackingump1/status/1241760059543244805
- virustotal.com/gui/file/79d3481bac60ac1ecc7e2d1a4b86bd…
183 more, and the report behind every indicator, in G0129.json.