logo

China-Linked Cyber Spies Blend Watering Hole, Supply Chain Attacks

ID: c4c58530-9dca-5a3d-b492-691bd0eaa48e

STIX ID: report--c4c58530-9dca-5a3d-b492-691bd0eaa48e

Feed Name: Dark Reading

Threat Score
90/100

Date Published: 2024-03-07

Date Updated: 2026-04-21

Author: Robert Lemos, Contributing Writer

...
...

Evasive Panda, a China-linked APT, ran a targeted campaign beginning in or before September 2023 that compromised Tibetan-focused websites and a Tibetan translation developer to deliver droppers and backdoors (MgBot and Nightdoor) via watering-hole, supply-chain/software-update, and phishing vectors; victims across India, Taiwan, Australia, the U.S., Hong Kong and others were impacted, and the activity demonstrates high technical sophistication and multiple attack vectors.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.