China, Turkiye, and India have been compromised by Chinese advanced persistent threat operation Evasive Panda with the MgBot backdoor in cyberespionage attacks involving poisoned Domain Name System requests between November 2022 and November 2024, according to The Hacker News.
Evasive Panda, also known as Daggerfly, Bronze Highland, and StormBamboo, has compromised multiple domains to distribute malicious updates for the SohuVA video streaming service, Baidu's iQIYI Video, Tencent QQ, and IObit Smart Defrag, which led to the delivery of a shellcode-launching loader and the eventual retrieval of a second-stage shellcode via DNS poisoning of the dictionary[.]com website, a report from Kaspersky revealed.
Another loader has been used to decrypt an MgBot malware variant, which then allows file gathering, keystroke logging, clipboard data collection, audio stream recording, and browser-stored credential exfiltration.
"The Evasive Panda threat actor has once again showcased its advanced capabilities, evading security measures with new techniques and tools while maintaining long-term persistence in targeted systems," said Kaspersky.
Evasive Panda, also known as Daggerfly, Bronze Highland, and StormBamboo, has compromised multiple domains to distribute malicious updates for the SohuVA video streaming service, Baidu's iQIYI Video, Tencent QQ, and IObit Smart Defrag, which led to the delivery of a shellcode-launching loader and the eventual retrieval of a second-stage shellcode via DNS poisoning of the dictionary[.]com website, a report from Kaspersky revealed.
Another loader has been used to decrypt an MgBot malware variant, which then allows file gathering, keystroke logging, clipboard data collection, audio stream recording, and browser-stored credential exfiltration.
"The Evasive Panda threat actor has once again showcased its advanced capabilities, evading security measures with new techniques and tools while maintaining long-term persistence in targeted systems," said Kaspersky.
