logo

Evasive Panda cyberespionage campaign uses DNS poisoning to install MgBot backdoor

ID: 159ac488-b8a3-511c-af2e-ab256823ce3d

STIX ID: report--159ac488-b8a3-511c-af2e-ab256823ce3d

Feed Name: Security Affairs

Threat Score
88/100

Date Published: 2025-12-29

Date Updated: 2026-04-22

Author: Pierluigi Paganini

...
...

Kaspersky researchers attribute a two-year targeted cyber-espionage campaign to the China-linked APT 'Evasive Panda' (aka Daggerfly/Bronze Highland/StormBamboo), which used DNS poisoning and fake software updates to deliver customized MgBot backdoors and stealthy loaders (including DLL sideloading and DPAPI/RC5-protected payloads) to victims in Türkiye, China, and India, maintaining long-term persistence and adapting payloads per host.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.