Threat Management, Threat Intelligence

DNS poisoning employed in Chinese cyberespionage campaign

Binary code with China flag

China, Turkiye, and India have been compromised by Chinese advanced persistent threat operation Evasive Panda with the MgBot backdoor in cyberespionage attacks involving poisoned Domain Name System requests between November 2022 and November 2024, according to The Hacker News.

Evasive Panda, also known as Daggerfly, Bronze Highland, and StormBamboo, has compromised multiple domains to distribute malicious updates for the SohuVA video streaming service, Baidu's iQIYI Video, Tencent QQ, and IObit Smart Defrag, which led to the delivery of a shellcode-launching loader and the eventual retrieval of a second-stage shellcode via DNS poisoning of the dictionary[.]com website, a report from Kaspersky revealed.

Another loader has been used to decrypt an MgBot malware variant, which then allows file gathering, keystroke logging, clipboard data collection, audio stream recording, and browser-stored credential exfiltration.

"The Evasive Panda threat actor has once again showcased its advanced capabilities, evading security measures with new techniques and tools while maintaining long-term persistence in targeted systems," said Kaspersky.

Get daily email updates

SC Media's daily must-read of the most current and pressing daily news

By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy.

You can skip this ad in 5 seconds