Evasive Panda leverages Monlam Festival to target Tibetans
ID: be55c199-3332-53b0-876e-110d2d7bd09a
STIX ID: report--be55c199-3332-53b0-876e-110d2d7bd09a
Feed Name: WeLiveSecurity (ESET Research)
ESET discovered an active cyberespionage campaign attributed to the China-aligned APT Evasive Panda that targeted Tibetan communities by compromising the Kagyu Monlam festival website (watering-hole) and trojanizing Tibetan language translation software installers. The attackers delivered malicious downloaders for Windows and macOS that fetched second-stage payloads, including the established MgBot backdoor and a previously undocumented Windows backdoor dubbed Nightdoor (which used Google Drive for C2). The report provides technical analysis of the infection chains, TTPs, targeted IP ranges across India, Taiwan, Hong Kong, Australia and the US, and a comprehensive set of IoCs and samples.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
