Mustang Panda
MITRE G0129Also known as HoneyMyte (Mustang Panda), RedDelta, MUSTANG PANDA, TA416, Earth Preta, Mustang Panda, Bronze President, HIVE0154, Stately Taurus
Reports
11
First seen
Nov 6, 2025
Last seen
Aug 5, 2026
Motivation
Espionage
Relationships
Filled ◆ = CVE exploited in the wild. Entities that appear together in Signalis reporting — co-mention, not confirmed collaboration. Reports naming many actors at once (weekly roundups) are excluded from relationship edges.
Targeting
Victim regions
India ×1
Top ATT&CK techniques
T1566 Phishing ×8T1190 Exploit Public-Facing Application ×6T1195 Supply Chain Compromise ×5T1078 Valid Accounts ×4T1005 Data from Local System ×4T1486 Data Encrypted for Impact ×4T1598 Phishing for Information ×3T1218 System Binary Proxy Execution ×3T1041 Exfiltration Over C2 Channel ×3T1583 Acquire Infrastructure ×2T1555 Credentials from Password Stores ×2T1598.003 Spearphishing Link ×2
Indicators
filename ×54cve ×15domain ×13ip_v4 ×1
Indicator values are available on Pro and via the API.
Associated CVEs
CVE-2025-29635 (exploited)CVE-2025-53690 (exploited)CVE-2025-55182 (exploited)CVE-2025-64155CVE-2025-8088 (exploited)CVE-2026-11645 (exploited)CVE-2026-1281 (exploited)CVE-2026-20045 (exploited)CVE-2026-20230 (exploited)CVE-2026-21509 (exploited)CVE-2026-28318 (exploited)CVE-2026-28950CVE-2026-33626 (exploited)CVE-2026-40372CVE-2026-42897 (exploited)
Recent reports
High