MUSTANG PANDA is a China-nexus cyber espionage group targeting NGOs with Mongolia-themed lures.
Analyst brief
MUSTANG PANDA is a China-nexus nation-state cyber espionage group. It primarily targets NGOs and civil society sectors in the United States and Germany, often using Mongolian-themed lures to gather intelligence on Mongolia-related matters. The actor relies on spearphishing links (T1566.002) for initial access and leverages PlugX, Cobalt Strike, and Mimikatz for credential theft and lateral movement, while also employing ARP Cache Poisoning (T1557.002) for network interception. Defenders should focus on email security and user awareness against malicious links, monitor for PlugX and Web Protocol-based C2 traffic, and remain vigilant for ARP spoofing indicators and suspicious use of tools like Mimikatz.
MUSTANG PANDA
BRONZE PRESIDENTHoneyMyteRed Lich
activenation-state
This threat actor targets nongovernmental organizations using Mongolian-themed lures for espionage purposes.
In April 2017, CrowdStrike Falcon Intelligence observed a previously unattributed actor group with a Chinese nexus targeting a U.S.-based think tank. Further analysis revealed a wider campaign with unique tactics, techniques, and procedures (TTPs). This adversary targets non-governmental organizations (NGOs) in general, but uses Mongolian language decoys and themes, suggesting this actor has a specific focus on gathering intelligence on Mongolia. These campaigns involve the use of shared malware like Poison Ivy or PlugX.
Recently, Falcon Intelligence observed new activity from MUSTANG PANDA, using a unique infection chain to target likely Mongolia-based victims. This newly observed activity uses a series of redirections and fileless, malicious implementations of legitimate tools to gain access to the targeted systems. Additionally, MUSTANG PANDA actors reused previously-observed legitimate domains to host files.
origin (suspected)
🇨🇳China· state-sponsoredattribution confidence: medium (50)