logo

China's 'Evasive Panda' APT Debuts High-End Cloud Hijacking

ID: a9be83ab-ace8-5a49-a257-dc99e03b6bad

STIX ID: report--a9be83ab-ace8-5a49-a257-dc99e03b6bad

Feed Name: Dark Reading

Threat Score
85/100

Date Published: 2024-10-29

Date Updated: 2026-04-21

Author: Tara Seals, Managing Editor, News, Dark Reading

...
...

ESET researchers uncovered CloudScout, a professional .NET post-compromise tool used by the China-linked APT Evasive Panda to access cloud services by hijacking authenticated web sessions via stolen browser cookies; integrated with MgBot and Nightdoor, CloudScout includes modules targeting Google Drive, Gmail, Outlook and at least seven other cloud apps to extract and compress data for exfiltration, effectively bypassing 2FA and IP tracking.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.