Splash247 Mustang Panda Escalates Cyberattacks on European Maritime Sector
Article Content
- •Mustang Panda targeted maritime organizations in seven EU states in 2025.
- •The group uses spear-phishing and compromised USB drives to deploy malware.
- •Maritime transport is classified as a cyber 'risk zone' by ENISA.
Chinese hacking group Mustang Panda has intensified cyberespionage campaigns targeting maritime organizations across at least seven EU member states throughout 2025. The European Union Agency for Cybersecurity (ENISA) reported that these attacks primarily focus on espionage and strategic intelligence collection, with Mustang Panda employing methods such as spear-phishing and the use of compromised USB drives to introduce malware, including customized versions of the PlugX remote-access tool. The maritime transport sector accounted for 16.4% of transport-related cyber incidents in the EU last year, highlighting its vulnerability. ENISA has classified maritime transport as a cyber 'risk zone' due to its strategic importance and reliance on interconnected systems. The group is believed to be state-sponsored, with prior attacks linked to EU diplomatic missions and Russian defense companies. Recent assessments indicate that vulnerabilities in shipboard systems are widespread, necessitating immediate risk treatment.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track Earth Preta and PlugX in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
China-Linked QTFY Group Targets Critical Infrastructure with Advanced Exploits The Joint Cybersecurity Advisory JCSA-20260826-01, released on August 26, 2026, details ongoing activities by the China-linked hacking group QTFY, attributed to Nanjing Xinjiuwei Network Technology Co. Active since 2018, QTFY employs platforms like QScan and QTRouter to exploit vulnerabilities in critical…
BambooToken Malware Exploits MQTT for Control of Infected Systems The BambooToken malware, discovered by Lumen's Black Lotus Labs, has been active since at least February 2023, targeting Windows and Linux systems across Asia and South America. It uses the MQTT protocol for command-and-control communications, allowing stealthy operations and evasion of detection. The malware was…