Threat Actor ๐Ÿ‡จ๐Ÿ‡ณ China

MUSTANG PANDA

Also known as: BRONZE PRESIDENT ยท HoneyMyte ยท Red Lich ยท TEMP.HEX ยท BASIN ยท Earth Preta ยท TA416 ยท Stately Taurus ยท LuminousMoth ยท Polaris ยท TANTALUM ยท Twill Typhoon

This threat actor targets nongovernmental organizations using Mongolian-themed lures for espionage purposes. In April 2017, CrowdStrike Falcon Intelligence observed a previously unattributed actor group with a Chinese nexus targeting a U.S.-based think tank. Further analysis revealed a wider campaign with unique tactics, techniques, and procedures (TTPs). This adversary targets non-governmental organizations (NGOs) in general, but uses Mongolian language decoys and themes, suggesting this actor has a specific focus on gathering intelligence on Mongolia. These campaigns involve the use of shared malware like Poison Ivy or PlugX. Recently, Falcon Intelligence observed new activity from MUSTANG PANDA, using a unique infection chain to target likely Mongolia-based victims. This newly observed activity uses a series of redirections and fileless, malicious implementations of legitimate tools to gain access to the targeted systems. Additionally, MUSTANG PANDA actors reused previously-observed legitimate domains to host files.

Indicators of Compromise 45

Domain black-popular[.]com Domain cdns3[.]51quickfox[.]cn Domain cloudtroe[.]giize[.]com Domain decoraat[.]net Domain employers[.]theworkpc[.]com Domain freeread[.]casacam[.]net Domain news[.]dursamjbataar[.]org Domain onedown[.]gesecole[.]net Domain sundanish[.]freeddns[.]org Domain torinarlabs[.]webredirect[.]org Domain us[.]lenovoappstore[.]com Domain video[.]dursamjbataar[.]org Domain whatismybestthing[.]com Filename AVK.exe Filename AVKTray.dat Filename Avk.dll Filename Client.dll Filename Invitation_Letter_No.02_2026.csproj Filename Invitation_Letter_No.02_2026.exe Filename cert.ini Filename ctxmui.dll Filename defender.exe Filename firebase-analytics-compat.js Filename firebase-app-compat.js Filename libngs.dll Filename loadcert.ini Filename msagent.sys Filename synchost.exe Filename time.ini Filename update.bin MD5 2d7c8780e97409770a9d4f31c66c9d63 MD5 9460e150e1981d5c165043520c5c12fe MD5 9717f005c5fb98e08d2ad983d88f94ee MD5 f518d8e5fe70d9090f6280c68a95998f SHA-1 9460e150e1981d5c165043520c5c12fe SHA-1 eb79558b037669792652a816e2c669de SHA-1 f518d8e5fe70d9090f6280c68a95998f SHA-256 29cd44aa2a51a200d82cca578d97dc13241bc906ea6a33b132c6ca567dc8f3ad SHA-256 46314092c8d00ab93cbbdc824b9fc39dec9303169163b9625bae3b1717d70ebc SHA-256 5f9af68db10b029453264cfc9b8eee4265549a2855bb79668ccfc571fb11f5fc SHA-256 6df8649bf4e233ee86a896ee8e5a3b3179c168ef927ac9283b945186f8629ee7 SHA-256 7ed0cd4115f3ff35c38d36cc50c6a13eba2d845554439a36108789cd1e05b176 SHA-256 8421e7995778faf1f2a902fb2c51d85ae39481f443b7b3186068d5c33c472d99 SHA-256 d293ded5a63679b81556d2c622c78be6253f500b6751d4eeb271e6500a23b21e SHA-256 de8ddc2451fb1305d76ab20661725d11c77625aeeaa1447faf3fbf56706c87f1

MITRE ATT&CK TTPs 27

Source Articles

Mustang Panda Adds Signed Windows Rootkit to CoolClient Backdoor for Stealth
The threat actor Mustang Panda, also known as HoneyMyte, has updated its CoolClient backdoor with a signed Windows kernel-mode rootkit to enhance stealth. The rootkit, deployed as msagent.sys, is digitally signed with a certificate from Nanjing Ranyi Technology Co., Ltd. and enables hiding of malicious processes, files, registry entries, and C2 network activity. The malware is typically deployed after initial compromise via PlugX and uses DLL sideloading through a legitimate Sangfor executable to execute malicious components and establish persistence.
hacker-news ยท2w ago
APT group HoneyMyte upgrades CoolClient: the backdoor gets a kernel-level Windows rootkit
The HoneyMyte APT group, also known as Mustang Panda, has upgraded its CoolClient backdoor with a kernel-mode Windows rootkit to enhance stealth and persistence. The new variant uses a signed kernel driver, msagent.sys, deployed as a Windows service to hide malicious processes, files, registry keys, and network connections. The malware chain begins with DLL sideloading via a renamed Sangfor executable (defender.exe), establishes persistence through scheduled tasks and registry entries, performs UAC bypass using RPC techniques, and injects into synchost.exe before deploying the driver. The driver communicates with user-mode components via IOCTLs and employs minifilter and registry callbacks to protect its artifacts.
securelist ยท2w ago
QuickFox Supply Chain Attack Delivers FDMTP Backdoor via Trojanized Windows Installer
A long-standing supply chain attack has affected QuickFox, a VPN and network acceleration tool, since at least August 2025. The malicious Windows installer, starting from version 3.0.51.0, delivers a backdoor called FDMTP via a trojanized Electron-based application. The attack uses a JavaScript loader that fingerprints the victim endpoint and downloads the payload from a malicious domain, cdns3.51quickfox[.]cn, which mimics the legitimate domain. The malware employs DLL side-loading to execute FDMTP, which communicates with a C2 server to exfiltrate system information and download additional plugins, targeting users such as Chinese expatriates and professionals interacting with Chinese speakers.
hacker-news ยท4w ago
PlugX Meeting Invitation via MSBuild and GDATA
A recent PlugX RAT campaign leverages a spear-phishing email with the subject 'Meeting Invitation' to deliver malicious payloads via DLL side-loading. The infection chain uses a legitimate G DATA antivirus executable (Avk.exe) to load a malicious DLL (Avk.dll), which decrypts and executes the payload from AVKTray.dat. The malware establishes persistence through a registry Run key and communicates with the C2 server at decoorat[.]net over HTTPS on port 443. The campaign demonstrates continued use of trusted binaries, XOR-based obfuscation, and API hashing techniques consistent with China-aligned threat actors.
lab52 ยท6mo ago