logo

Evasive Panda APT Using AitM Attack and DNS Poisoning to Deliver Malware

ID: 250adb95-9626-55d3-a3b7-67e7d1e88504

STIX ID: report--250adb95-9626-55d3-a3b7-67e7d1e88504

Feed Name: cybersecurityNews.com

Threat Score
86/100

Date Published: 2025-12-24

Date Updated: 2026-04-21

Author: Tushar Subhra Dutta

...
...

The report describes Evasive Panda (aka Bronze Highland/Daggerfly/StormBamboo) conducting targeted campaigns from Nov 2022 through Nov 2024 that use DNS poisoning and adversary-in-the-middle attacks to deliver MgBot disguised as legitimate software updates; the multi-stage infection employs XOR/RC5/DPAPI hybrid encryption, DLL sideloading, and process injection to evade detection and maintain persistence, impacting victims in Türkiye, China, and India.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.