Skip to content
Mustang Panda Escalates Cyberattacks on European Maritime Sector

Mustang Panda Escalates Cyberattacks on European Maritime Sector

First seen 23 Sep 2026, 14:55 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster September 23, 2026 at 16:54 UTC
  • Mustang Panda targeted maritime organizations in seven EU states in 2025.
  • The group uses spear-phishing and compromised USB drives to deploy malware.
  • Maritime transport is classified as a cyber 'risk zone' by ENISA.

Chinese hacking group Mustang Panda has intensified cyberespionage campaigns targeting maritime organizations across at least seven EU member states throughout 2025. The European Union Agency for Cybersecurity (ENISA) reported that these attacks primarily focus on espionage and strategic intelligence collection, with Mustang Panda employing methods such as spear-phishing and the use of compromised USB drives to introduce malware, including customized versions of the PlugX remote-access tool. The maritime transport sector accounted for 16.4% of transport-related cyber incidents in the EU last year, highlighting its vulnerability. ENISA has classified maritime transport as a cyber 'risk zone' due to its strategic importance and reliance on interconnected systems. The group is believed to be state-sponsored, with prior attacks linked to EU diplomatic missions and Russian defense companies. Recent assessments indicate that vulnerabilities in shipboard systems are widespread, necessitating immediate risk treatment.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2025-01-01
Mustang Panda campaigns reported
ENISA reported ongoing cyberespionage campaigns by Mustang Panda against maritime organizations in Europe.
Splash247
2025-01-05
Cyber incidents in maritime transport surge
Recorded maritime cyber incidents increased by 103% during 2025, with USB devices being a primary infection vector.
Splash247
2025-12-31
ENISA Threat Landscape 2026 published
ENISA's report highlighted Mustang Panda's sustained attacks on maritime organizations and classified the sector as a cyber risk zone.
Ua.News

More articles in this cluster (2)

Following this threat?

Track Earth Preta and PlugX in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed