logo

Chinese hackers deploy new Macma macOS backdoor version

ID: 0c53104a-f584-53f2-af5e-f363656f2d83

STIX ID: report--0c53104a-f584-53f2-af5e-f363656f2d83

Feed Name: Bleeping Computer

Threat Score
86/100

Date Published: 2024-07-23

Date Updated: 2026-07-18

Author: Bill Toulas

...
...

Symantec and other vendors observed the Chinese APT 'Evasive Panda' using refreshed tooling — updated Macma macOS backdoors, Nightdoor Windows backdoors, and the MgBot modular framework — to conduct espionage against Taiwanese organizations and an NGO in China, leveraging an Apache HTTP server flaw and possible supply-chain/AITM delivery; analysis highlights a shared, custom cross-platform library (magic strings 'inp' and 'tim'), C2 overlap, anti-analysis features, and persistence mechanisms.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.