Free tools Windows power users keep installed
One-click scans. No signup required.
ESET documents Mustang Panda targeting the Vatican in 2020. Its later reporting describes the group experimenting with Korplug loaders and using malicious USB drives in operations against government and maritime organizations from October 2024 through March 2025. The cited reporting does not establish a new Vatican attack or show that the later tool changes were used against the Vatican.
What is Mustang Panda?
Mustang Panda is the name ESET uses for a cyber-espionage group it assesses as likely based in China. ESET also lists the aliases TA416, RedDelta, PKPLUG, Earth Preta, and Stately Taurus. These are researcher assessments and naming conventions, not confirmation of the operators’ identities. ESET’s APT Reports group profile describes victims mainly in East and Southeast Asia, with a focus on Mongolia; that observation is not a complete census of the group’s targets.
Did Mustang Panda target the Vatican?
Yes. ESET’s group profile says Mustang Panda was known for a campaign targeting the Vatican in 2020. The profile information cited here does not establish which Vatican systems were affected, how access was obtained, what consequences followed, or which specific tool versions were involved. It therefore supports saying that the group targeted the Vatican, but not adding a more detailed account of the incident.
What tool changes did ESET report?
For October 2024 through March 2025, ESET reported Mustang Panda activity targeting governmental institutions and maritime transportation companies. The report names Korplug loaders and malicious USB drives, and says the group experimented with Korplug loaders built using different file formats and programming languages. It also describes observations across several European countries. ESET’s activity report for Q4 2024–Q1 2025 is the source for this later operational context.
Windows Errors? Fix Them Before They Spread
Repair common Windows errors and clear accumulated junk for a smoother, more stable PC - no reinstall needed.Free scan · no reinstallCrashes, No Sound, or Screen Glitches?
Random freezes, missing sound and display glitches usually trace back to one bad driver. Find and replace yours safely.Free scan · under a minute#1 Best Overall
Korplug is the loader family named in that report. The reporting summary does not provide a complete technical breakdown for reconstructing an intrusion chain, so exact versions, hashes, and a specific sequence of infection steps cannot be established from it. Nor does it say that these loader experiments were deployed in the 2020 Vatican campaign.
How the documented activity periods differ
| Period | Targets and geography described | Tools or mechanisms named | Vatican connection established? |
|---|---|---|---|
| 2020 | Vatican campaign, according to ESET’s group profile; further operational detail is not stated there. | Specific tool versions and delivery details are not stated in the cited profile. | Yes. ESET identifies a campaign targeting the Vatican. |
| October 2024–March 2025 | Governmental institutions and maritime transportation companies, including activity observed in several European countries. | Korplug loaders and malicious USB drives; experimentation with loaders using different file formats and programming languages. | No. The report describes later operations, not a new Vatican incident. |
How to interpret the reporting
The chronology matters: a group’s later experimentation does not show that the same tools were used in an earlier campaign, or that the earlier target was attacked again. In the sources cited here, ESET establishes Vatican targeting in 2020 and separately reports broader government and maritime operations in October 2024–March 2025. It does not connect those later tool changes to a new Vatican intrusion.
MITRE ATT&CK’s Mustang Panda profile provides a maintained reference for reported group associations and technique vocabulary, including ingress tool transfer, use of legitimate software tools for execution, and DLL sideloading. ATT&CK aggregates reporting; a technique listed in the profile should not be read as proof it occurred in a particular Vatican incident unless an underlying analysis makes that connection.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.What this means for institutional defenders
The reports support treating removable media and changing loader implementations as relevant context when reviewing Mustang Panda activity, but they do not establish that any specific institution is currently under attack. Organizations can use the dated ESET reporting alongside their own threat-intelligence and incident-response procedures. A technique reference such as MITRE ATT&CK can help teams organize detections and investigations, while attribution and incident-specific conclusions should remain tied to the evidence available for the case.
Quick Recap
Best Value
Rank #4
Rank #3
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

