CyberHappenings logo

Track cybersecurity events as they unfold. Sourced timelines. Filter, sort, and browse. Fast, privacy‑respecting. No invasive ads, no tracking.

Evasive Panda Conducts DNS Poisoning Campaign to Deploy MgBot Malware

First reported
Last updated
1 unique sources, 1 articles

Summary

Hide ▲

The China-linked APT group Evasive Panda (also known as Bronze Highland, Daggerfly, and StormBamboo) has been identified as responsible for a targeted cyber espionage campaign that utilized DNS poisoning to deliver the MgBot backdoor malware. The campaign, which took place between November 2022 and November 2024, targeted victims in Türkiye, China, and India. The attackers employed adversary-in-the-middle (AitM) techniques, including dropping loaders in specific locations and storing encrypted malware parts on attacker-controlled servers. This campaign highlights the group's advanced capabilities in evading security measures and maintaining long-term persistence in compromised systems.

Timeline

  1. 26.12.2025 16:44 1 articles · 23h ago

    Evasive Panda Conducts DNS Poisoning Campaign to Deploy MgBot Malware

    Between November 2022 and November 2024, the China-linked APT group Evasive Panda conducted a targeted cyber espionage campaign that utilized DNS poisoning to deliver the MgBot backdoor malware. The campaign targeted victims in Türkiye, China, and India, employing adversary-in-the-middle (AitM) techniques to drop loaders and store encrypted malware parts on attacker-controlled servers. The attackers used fake updates for third-party software such as SohuVA, Baidu's iQIYI Video, IObit Smart Defrag, and Tencent QQ to deliver the malware. The second-stage payload was delivered as a PNG image file and was unique to each victim to bypass detection. The malware used a custom encryption algorithm to complicate analysis and ensure persistence. MgBot is a modular implant capable of harvesting files, logging keystrokes, gathering clipboard data, recording audio streams, and stealing credentials from web browsers.

    Show sources

Information Snippets