SEPTEMBER 23, 2025

Mustang Panda, also identified as Earth Preta, Bronze President, TA416, RedDelta, and HIVE0154, is still one of the most active China-aligned APT groups in 2025. Mustang Panda is a cyber-espionage focused group actively working to adapt the tools and techniques it uses to maintain persistence within the targeted strategic organizations in Asia, Europe, and beyond.
The campaigns demonstrate the changing nature of state-sponsored espionage, as the China-linked adversaries exhibit their ongoing focus on long-term intelligence collection.
Identity and Motivation
The group’s motive clearly outlined goals that fit Beijing’s geopolitical and strategic interests, particularly for neighbouring states, European partners, and international organizations active in maritime security, policy, and law enforcement.
The tradecraft of Mustang Panda continues to adapt while at the same time, keeping some familiar tools and delivery mechanisms.
📊 Visual Aid: TTPs Diagram Initial Access → Execution → Persistence → C2/Exfiltration
| | | |
Phishing Droppers VPNs, DLLs PlugX, ToneShell
LNK+PDF Korplug Side-loading XOR C2
USB Malware ToneShell SoftEther VPN Data Theft
• 2025 (Myanmar): Deployment of a “Frankenstein” ToneShell backdoor variant.
• 2025 (Thailand): Targeting of the Royal Thai Police with a Yokai backdoor delivered via LNK + PDF decoy.
• 2025 (Europe): Continuing operations against European Union governments with maritime transportation operations using usb-based loaders and Korplug.
• 2024-2025: Campaigns that are combining legitimate applications along with malware with the intention of bypassing detection, as noted by Trend Micro.
• Historical: High-volume usage of PlugX/Korplug with DLL side-loading against NGOs, religious organizations, and governments throughout Asia and Europe.
Since late 2024 through all of 2025, Mustang Panda transitioned from single-vector initial access to the addition of USB media, complementing its phishing-heavy operations.
The level of commitment demonstrated by this APT group has clearly demonstrated an enduring cycle of espionage operations that align with Beijing’s foreign policy and national security objectives.
Mustang Panda is a great example of the amount of persistence and adaptability China-aligned APT groups are capable of. The operational activity observed across the APAC, Europe, and North America demonstrates a continuous evolution from PlugX-centric operations to newer malware families like ToneShell and Yokai.
The specific targeting and operational emphasis exhibited in its campaigns against diplomatic, government, and law enforcement-related organizations demonstrate continued strategic framing priorities for the Chinese State.
Takeaways for Defenders
The continuation of Mustang Panda’s operations in 2025 fully encapsulates the reality that China’s cyber-espionage apparatus is both persistent and adaptive in nature, and requires defenders to anticipate the continued evolution of the tools and techniques used in different campaigns.
You can download and review the sheet for all the details!

Take control of your digital security with an exclusive demo of our powerful threat management platform.