Evasive Panda cyberespionage campaign uses DNS poisoning to install MgBot backdoor
ID: 159ac488-b8a3-511c-af2e-ab256823ce3d
STIX ID: report--159ac488-b8a3-511c-af2e-ab256823ce3d
Feed Name: Security Affairs
Threat Score
Kaspersky researchers attribute a two-year targeted cyber-espionage campaign to the China-linked APT 'Evasive Panda' (aka Daggerfly/Bronze Highland/StormBamboo), which used DNS poisoning and fake software updates to deliver customized MgBot backdoors and stealthy loaders (including DLL sideloading and DPAPI/RC5-protected payloads) to victims in Türkiye, China, and India, maintaining long-term persistence and adapting payloads per host.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
