{
  "name": "Adversary Atlas API",
  "version": "1.0.0",
  "description": "Read-only JSON API over the Adversary Atlas threat actor dataset. Statically generated at build time; no authentication, no rate limits.",
  "generated": "2026-07-31T01:06:07.226Z",
  "datasetCurrentAsOf": "2025-09-01",
  "license": "Data compiled from public primary sources; see /methodology/ for sourcing.",
  "actor": {
    "id": "mustang-panda",
    "slug": "mustang-panda",
    "name": "Mustang Panda",
    "shortName": "Mustang Panda",
    "country": "China",
    "countryCode": "CN",
    "sponsorship": "state-sponsored",
    "status": "active",
    "activeSince": "2014",
    "prominence": 84,
    "mitreGroupId": "G0129",
    "malpediaSlug": "mustang_panda",
    "tagline": "The highest-volume Chinese espionage operation against Europe and Southeast Asia — and the subject of an FBI operation that deleted its malware from 4,258 U.S. computers.",
    "bio": "Mustang Panda runs the broadest-reach Chinese espionage operation currently active, focused on government ministries, NGOs, and religious and ethnic minority organisations across Southeast Asia, Europe, and the Pacific.\n\nIts targeting reflects PRC political priorities beyond conventional intelligence value: Tibetan and Uyghur diaspora organisations, the Vatican and Catholic institutions in Hong Kong, Mongolian and Myanmar government entities, and European foreign ministries — with a marked increase in EU targeting after February 2022, as European policy on Russia and Ukraine became a collection priority.\n\nThe group's toolset centres on PlugX, an ageing but relentlessly maintained backdoor delivered almost exclusively through DLL side-loading: a legitimately signed executable from a trusted vendor is shipped alongside a malicious DLL it loads on startup. Because the running process carries a valid signature, allow-listing and reputation-based controls frequently pass it.\n\nA self-propagating USB variant produced a distinctive problem — it spread far beyond its intended targets, leaving PlugX on thousands of unrelated machines worldwide. In January 2025 the FBI and French authorities executed a court-authorised operation using PlugX's own self-delete command to remove the malware from 4,258 U.S.-based computers.",
    "attribution": {
      "sponsor": "China",
      "service": "People's Republic of China state-sponsored (specific service not publicly designated)",
      "confidence": "high",
      "summary": "Assessed as PRC state-sponsored by consistent industry reporting from Secureworks, ESET, Proofpoint, Recorded Future, and Trend Micro, based on targeting aligned with PRC political interests, Chinese-language artifacts, and operational timing consistent with China Standard Time working hours. No specific service has been publicly designated and no individuals have been indicted; the January 2025 DOJ action was a technical disruption rather than an attribution to named persons.",
      "sources": [
        {
          "org": "U.S. Department of Justice / FBI",
          "title": "Justice Department and FBI Conduct International Operation to Delete Malware Used by China-Backed Hackers",
          "url": "https://www.justice.gov/opa/pr/justice-department-and-fbi-conduct-international-operation-delete-malware-used-china-backed",
          "date": "2025-01-14"
        },
        {
          "org": "Secureworks CTU",
          "title": "BRONZE PRESIDENT Targets NGOs",
          "url": "https://www.secureworks.com/research/bronze-president-targets-ngos",
          "date": "2019-12-29"
        }
      ]
    },
    "motivations": [
      "espionage"
    ],
    "targetSectors": [
      "Government",
      "NGO & Civil Society",
      "Diplomatic",
      "Think Tanks & Academia",
      "Media & Journalism",
      "Education",
      "Defense",
      "Political Organizations"
    ],
    "targetCountries": [
      "Myanmar",
      "Vietnam",
      "Philippines",
      "Mongolia",
      "Taiwan",
      "Belgium",
      "Germany",
      "Hungary",
      "Australia",
      "Vatican City",
      "Indonesia"
    ],
    "aliases": [
      {
        "org": "mitre",
        "name": "Mustang Panda",
        "url": "https://attack.mitre.org/groups/G0129/",
        "correlation": "exact"
      },
      {
        "org": "microsoft",
        "name": "Twill Typhoon",
        "correlation": "exact",
        "note": "Formerly TANTALUM"
      },
      {
        "org": "microsoft",
        "name": "TANTALUM",
        "correlation": "exact",
        "note": "Retired designator"
      },
      {
        "org": "crowdstrike",
        "name": "Mustang Panda",
        "correlation": "exact"
      },
      {
        "org": "secureworks",
        "name": "BRONZE PRESIDENT",
        "correlation": "exact"
      },
      {
        "org": "unit42",
        "name": "Stately Taurus",
        "correlation": "exact"
      },
      {
        "org": "trendmicro",
        "name": "Earth Preta",
        "correlation": "exact"
      },
      {
        "org": "recordedfuture",
        "name": "RedDelta",
        "correlation": "exact"
      },
      {
        "org": "proofpoint",
        "name": "TA416",
        "correlation": "exact"
      },
      {
        "org": "eset",
        "name": "Mustang Panda",
        "correlation": "exact"
      },
      {
        "org": "kaspersky",
        "name": "HoneyMyte",
        "correlation": "exact"
      },
      {
        "org": "mandiant",
        "name": "Camaro Dragon",
        "correlation": "partial",
        "note": "Check Point designator for an overlapping router-implant cluster"
      }
    ],
    "tools": [
      {
        "name": "PlugX",
        "type": "backdoor",
        "custom": true,
        "description": "The group's flagship implant, delivered via DLL side-loading against a signed legitimate executable. Continuously maintained since roughly 2008 across many Chinese groups.",
        "malpediaSlug": "win.plugx"
      },
      {
        "name": "PUBLOAD",
        "type": "loader",
        "custom": true,
        "description": "Staged downloader retrieving PlugX from attacker infrastructure, often via a decoy document."
      },
      {
        "name": "TONESHELL",
        "type": "backdoor",
        "custom": true,
        "description": "Shellcode-based backdoor with in-memory execution, used in more recent European campaigns."
      },
      {
        "name": "HIUPAN / MISTCLOAK",
        "type": "malware",
        "custom": true,
        "description": "USB propagation modules that spread PlugX to removable media, producing widespread incidental infection."
      },
      {
        "name": "Cobalt Strike",
        "type": "framework",
        "custom": false,
        "description": "Deployed for interactive access after initial PlugX foothold."
      },
      {
        "name": "RTF template injection",
        "type": "utility",
        "custom": false,
        "description": "Documents fetching weaponised remote templates only when opened by intended targets."
      }
    ],
    "techniques": [
      {
        "tCode": "T1566.001",
        "name": "Phishing: Spearphishing Attachment",
        "tactic": "Initial Access",
        "note": "Geopolitically themed lures matched precisely to the target's portfolio"
      },
      {
        "tCode": "T1574.002",
        "name": "Hijack Execution Flow: DLL Side-Loading",
        "tactic": "Defense Evasion",
        "note": "Signature technique — legitimately signed binaries loading malicious DLLs"
      },
      {
        "tCode": "T1091",
        "name": "Replication Through Removable Media",
        "tactic": "Lateral Movement",
        "note": "USB propagation reaching air-gapped and disconnected systems"
      },
      {
        "tCode": "T1221",
        "name": "Template Injection",
        "tactic": "Defense Evasion"
      },
      {
        "tCode": "T1547.001",
        "name": "Boot or Logon Autostart Execution: Registry Run Keys",
        "tactic": "Persistence"
      },
      {
        "tCode": "T1027.013",
        "name": "Obfuscated Files or Information: Encrypted/Encoded File",
        "tactic": "Defense Evasion"
      },
      {
        "tCode": "T1071.001",
        "name": "Application Layer Protocol: Web Protocols",
        "tactic": "Command and Control"
      },
      {
        "tCode": "T1102",
        "name": "Web Service",
        "tactic": "Command and Control",
        "note": "Dropbox and Google Drive used for staging and exfiltration"
      },
      {
        "tCode": "T1560.001",
        "name": "Archive Collected Data: Archive via Utility",
        "tactic": "Collection",
        "note": "RAR archives of documents staged before exfiltration"
      },
      {
        "tCode": "T1005",
        "name": "Data from Local System",
        "tactic": "Collection"
      }
    ],
    "cves": [
      {
        "cveId": "CVE-2017-0199",
        "firstExploited": "2019-01-01",
        "usage": "OLE2link RTF exploit delivering PlugX loaders in phishing against Southeast Asian government targets.",
        "source": {
          "org": "Anomali",
          "title": "Mustang Panda Riding Along with PlugX",
          "url": "https://www.anomali.com/blog/china-based-apt-mustang-panda-targets-minority-groups-public-and-private-sector-organizations",
          "date": "2019-10-08"
        }
      },
      {
        "cveId": "CVE-2017-11882",
        "firstExploited": "2019-03-01",
        "usage": "Equation Editor overflow in lure documents targeting NGOs and minority organisations.",
        "source": {
          "org": "Secureworks CTU",
          "title": "BRONZE PRESIDENT Targets NGOs",
          "url": "https://www.secureworks.com/research/bronze-president-targets-ngos",
          "date": "2019-12-29"
        }
      },
      {
        "cveId": "CVE-2022-30190",
        "firstExploited": "2022-06-01",
        "usage": "Follina MSDT exploit used in campaigns against European government and diplomatic targets.",
        "source": {
          "org": "Proofpoint",
          "title": "Chinese APT TA416 resumes activity against European diplomatic entities",
          "url": "https://www.proofpoint.com/us/blog/threat-insight/chinese-apt-ta416-resumes-targeting-of-europe",
          "date": "2022-08-01"
        }
      }
    ],
    "relationships": [
      {
        "relatedActorId": "apt10",
        "type": "shared-tooling",
        "confidence": "high",
        "note": "PlugX is shared across many Chinese groups, complicating attribution when it is the only artifact present."
      },
      {
        "relatedActorId": "apt41",
        "type": "same-sponsor",
        "confidence": "low",
        "note": "Both PRC state-nexus; shared use of DLL side-loading tradecraft and PlugX lineage tooling."
      }
    ],
    "reports": [
      {
        "org": "Secureworks CTU",
        "title": "BRONZE PRESIDENT Targets NGOs",
        "url": "https://www.secureworks.com/research/bronze-president-targets-ngos",
        "date": "2019-12-29"
      },
      {
        "org": "Trend Micro",
        "title": "Earth Preta Spear-Phishing Governments Worldwide",
        "url": "https://www.trendmicro.com/en_us/research/22/k/earth-preta-spear-phishing-governments-worldwide.html",
        "date": "2022-11-18"
      },
      {
        "org": "U.S. Department of Justice / FBI",
        "title": "International operation deletes PlugX malware from 4,258 U.S. computers",
        "url": "https://www.justice.gov/opa/pr/justice-department-and-fbi-conduct-international-operation-delete-malware-used-china-backed",
        "date": "2025-01-14"
      },
      {
        "org": "Recorded Future Insikt Group",
        "title": "RedDelta Targets Mongolia, Taiwan, and Southeast Asia",
        "url": "https://www.recordedfuture.com/research/chinese-state-sponsored-group-reddelta-targets-mongolia-taiwan-southeast-asia",
        "date": "2025-01-16"
      }
    ],
    "campaigns": [
      {
        "id": "plugx-takedown",
        "actorId": "mustang-panda",
        "name": "PlugX Global Infection and FBI Removal",
        "date": "2022-09-01",
        "endDate": "2025-01-14",
        "significance": "major",
        "targetSectors": [
          "Government",
          "NGO & Civil Society",
          "Diplomatic",
          "Education"
        ],
        "targetCountries": [
          "United States",
          "France",
          "Germany",
          "Myanmar",
          "Vietnam",
          "Philippines"
        ],
        "cveIds": [],
        "summary": "A self-propagating USB variant of PlugX spread far beyond its intended targets, leaving the implant on thousands of unrelated machines worldwide. In January 2025 the FBI and French authorities used PlugX's own self-delete command to remove it from 4,258 U.S.-based computers under court authorisation.",
        "sources": [
          {
            "org": "U.S. Department of Justice / FBI",
            "title": "International operation deletes PlugX malware from 4,258 U.S. computers",
            "url": "https://www.justice.gov/opa/pr/justice-department-and-fbi-conduct-international-operation-delete-malware-used-china-backed",
            "date": "2025-01-14"
          }
        ]
      }
    ],
    "flag": "🇨🇳",
    "profile": "/apt/mustang-panda/"
  }
}