logo

China's Evasive Panda Attacks ISP to Send Malicious Software Updates

ID: adbb5ad6-482b-57e1-926d-077d489ea5cb

STIX ID: report--adbb5ad6-482b-57e1-926d-077d489ea5cb

Feed Name: Dark Reading

Threat Score
85/100

Date Published: 2024-08-05

Date Updated: 2026-04-21

Author: Elizabeth Montalbano, Contributing Writer

...
...

Researchers at Volexity found that the China-linked APT known as Evasive Panda (aka StormBamboo/DaggerFly) compromised an ISP to poison DNS responses and redirect insecure HTTP software update requests to attacker-controlled servers, resulting in installation of backdoors (Macma), MGBot/Pocostick variants, and post-exploitation tooling (including a malicious browser extension) to exfiltrate email and credentials; Volexity provided IOCs and detection rules and coordinated mitigation with the affected ISP.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.