Chinese hackers deploy new Macma macOS backdoor version
ID: 0c53104a-f584-53f2-af5e-f363656f2d83
STIX ID: report--0c53104a-f584-53f2-af5e-f363656f2d83
Feed Name: Bleeping Computer
Symantec and other vendors observed the Chinese APT 'Evasive Panda' using refreshed tooling — updated Macma macOS backdoors, Nightdoor Windows backdoors, and the MgBot modular framework — to conduct espionage against Taiwanese organizations and an NGO in China, leveraging an Apache HTTP server flaw and possible supply-chain/AITM delivery; analysis highlights a shared, custom cross-platform library (magic strings 'inp' and 'tim'), C2 overlap, anti-analysis features, and persistence mechanisms.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
