China's Evasive Panda Attacks ISP to Send Malicious Software Updates
ID: adbb5ad6-482b-57e1-926d-077d489ea5cb
STIX ID: report--adbb5ad6-482b-57e1-926d-077d489ea5cb
Feed Name: Dark Reading
Date Published: 2024-08-05
Date Updated: 2026-04-21
Author: Elizabeth Montalbano, Contributing Writer
Researchers at Volexity found that the China-linked APT known as Evasive Panda (aka StormBamboo/DaggerFly) compromised an ISP to poison DNS responses and redirect insecure HTTP software update requests to attacker-controlled servers, resulting in installation of backdoors (Macma), MGBot/Pocostick variants, and post-exploitation tooling (including a malicious browser extension) to exfiltrate email and credentials; Volexity provided IOCs and detection rules and coordinated mitigation with the affected ISP.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
