logo

Evasive Panda leverages Monlam Festival to target Tibetans

ID: be55c199-3332-53b0-876e-110d2d7bd09a

STIX ID: report--be55c199-3332-53b0-876e-110d2d7bd09a

Feed Name: WeLiveSecurity (ESET Research)

Threat Score
90/100

Date Published: 2024-03-07

Date Updated: 2026-05-01

...
...

ESET discovered an active cyberespionage campaign attributed to the China-aligned APT Evasive Panda that targeted Tibetan communities by compromising the Kagyu Monlam festival website (watering-hole) and trojanizing Tibetan language translation software installers. The attackers delivered malicious downloaders for Windows and macOS that fetched second-stage payloads, including the established MgBot backdoor and a previously undocumented Windows backdoor dubbed Nightdoor (which used Google Drive for C2). The report provides technical analysis of the infection chains, TTPs, targeted IP ranges across India, Taiwan, Hong Kong, Australia and the US, and a comprehensive set of IoCs and samples.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.