CyberSecurityBoardThreat Intel · CVEs · Products

Tag: Mustang Panda

Malware

CoolClient Backdoor Analysis

CoolClient is a modular backdoor used by Mustang Panda. It supports keylogging, clipboard theft, credential harvesting, file management, and system reconnaissance. The…

backdoor C2 CoolClient Mustang Panda
August 14, 2026
Attack Groups

Mustang Panda

[Mustang Panda](https://attack.mitre.org/groups/G0129) is a China-based cyber espionage threat actor that has been conducting operations since at least 2012. [Mustang Panda](https://attack.mitre.org/groups/G0129) has been…

BRONZE PRESIDENT CAMARO DRAGON ClumsyToad EARTH PRETA
July 31, 2026
Malware

SHARDLOADER: DLL Sideloading Malware Loader

SHARDLOADER is a malware loader used by Mustang Panda that sideloads a malicious DLL through legitimately signed binaries like Solid PDF Creator…

DLL Sideloading loader Mustang Panda SHARDLOADER
June 29, 2026
Malware

MINIRECON: Toneshell Variant Backdoor

MINIRECON is a reworked variant of the Toneshell backdoor, beaconing over WebSocket on HTTPS, used by Mustang Panda.

backdoor MINIRECON Mustang Panda Toneshell
June 29, 2026
Malware

ZOHOMURK: Zoho WorkDrive Dead Drop Malware

ZOHOMURK is a novel malware that uses hardcoded Zoho OAuth credentials to turn an attacker-controlled WorkDrive account into a dead drop for…

dead drop exfiltration Mustang Panda Zoho WorkDrive
June 29, 2026