Evasive Panda APT Using AitM Attack and DNS Poisoning to Deliver Malware
ID: 250adb95-9626-55d3-a3b7-67e7d1e88504
STIX ID: report--250adb95-9626-55d3-a3b7-67e7d1e88504
Feed Name: cybersecurityNews.com
Threat Score
The report describes Evasive Panda (aka Bronze Highland/Daggerfly/StormBamboo) conducting targeted campaigns from Nov 2022 through Nov 2024 that use DNS poisoning and adversary-in-the-middle attacks to deliver MgBot disguised as legitimate software updates; the multi-stage infection employs XOR/RC5/DPAPI hybrid encryption, DLL sideloading, and process injection to evade detection and maintain persistence, impacting victims in Türkiye, China, and India.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
