China's 'Evasive Panda' APT Debuts High-End Cloud Hijacking
ID: a9be83ab-ace8-5a49-a257-dc99e03b6bad
STIX ID: report--a9be83ab-ace8-5a49-a257-dc99e03b6bad
Feed Name: Dark Reading
Date Published: 2024-10-29
Date Updated: 2026-04-21
Author: Tara Seals, Managing Editor, News, Dark Reading
ESET researchers uncovered CloudScout, a professional .NET post-compromise tool used by the China-linked APT Evasive Panda to access cloud services by hijacking authenticated web sessions via stolen browser cookies; integrated with MgBot and Nightdoor, CloudScout includes modules targeting Google Drive, Gmail, Outlook and at least seven other cloud apps to extract and compress data for exfiltration, effectively bypassing 2FA and IP tracking.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
