logo

Hackers breach ISP to poison software updates with malware

ID: eb30261e-364c-5260-8ac8-a9b734e1036b

STIX ID: report--eb30261e-364c-5260-8ac8-a9b734e1036b

Feed Name: Bleeping Computer

Threat Score
88/100

Date Published: 2024-08-03

Date Updated: 2026-07-18

Author: Sergiu Gatlan

...
...

Volexity reported that the Chinese APT StormBamboo compromised an ISP and abused insecure HTTP-based software update workflows and DNS poisoning to push backdoored installers (including MACMA and POCOSTICK/MGBot) to Windows and macOS victims; the attackers also installed a malicious Chrome extension (ReloadText) to steal cookies and mail data. The activity suggests a supply-chain or adversary-in-the-middle approach, with corroborating telemetry and prior related incidents observed by ESET and Symantec.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.