logo

Chinese State Hackers Target Tibetans with Supply Chain, Watering Hole Attacks

ID: 2a673ece-632c-5f59-b451-4df35b46937d

STIX ID: report--2a673ece-632c-5f59-b451-4df35b46937d

Feed Name: The Hacker News

Threat Score
85/100

Date Published: 2024-03-07

Date Updated: 2026-04-24

Author: [email protected] (The Hacker News)

...
...

**Evasive Panda** conducted targeted watering-hole and supply-chain attacks (discovered Jan 2024, active since at least Sep 2023) against Tibetan users and a Tibetan software vendor to distribute trojanized Windows/macOS installers and downloaders that deploy the MgBot backdoor and a newly observed Windows implant dubbed *Nightdoor*, abusing Google Drive API for C2 and leveraging IP-based targeting across India, Taiwan, Hong Kong, Australia, and the U.S.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.